Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
231 results
CVE-2021-40444 preview

CVE-2021-40444

GitHubklezvirus/cve-2021-40444

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

command-and-controleducationexploitation+4
8362 years ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5621 days ago
awesome-industrial-control-system-security preview

awesome-industrial-control-system-security

GitHubhslatman/awesome-industrial-control-system-security

A curated list of resources related to Industrial Control System (ICS) security.

curated-resourcesexploitationfuzzing+9
2.0k0 years ago
juice-shop preview

juice-shop

GitHubjuice-shop/juice-shop

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

ctfeducationlabs-practice+3
14.0k2 days ago
atomicvulns preview

atomicvulns

GitHubdoretox/atomicvulns

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

ctfeducationlabs-practice+5
239 days ago
awesome-shodan-queries preview

awesome-shodan-queries

GitHubjakejarvis/awesome-shodan-queries

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

curated-resourceseducationinformation-gathering+5
7.8k6 years ago
CVE-2025-31702 preview

CVE-2025-31702

GitHubitres-labs/cve-2025-31702

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

digital-forensicsexploitationincident-response+3
109 months ago
shodan-dorks preview

shodan-dorks

GitHubnullfuzz-pentest/shodan-dorks

Shodan Dorks

curated-resourcesinformation-gatheringiot-security+4
5475 months ago
shodan-eye preview

shodan-eye

GitHubbullseye0/shodan-eye

Shodan Eye This tool collects all the information about all devices directly connected to the internet using the specified keywords that you enter.…

information-gatheringnetwork-securityosint+2
1.4k8 days ago
zeek-jetdirect preview

zeek-jetdirect

GitHubdopheide-esnet/zeek-jetdirect

Zeek package to detect exploitation attempts of CVE-2017-2741 targeting HP JetDirect printers via network traffic analysis.

exploitationintrusion-detectioniot-security+2
5 years ago
CVE-2024-7120 preview

CVE-2024-7120

GitHubgh-ost00/cve-2024-7120

Proof-of-concept exploit for CVE-2024-7120 command injection vulnerability in RAISECOM gateway devices. Provides exploitation details, affected…

command-and-controlexploitationiot-security+3
82 years ago
laf preview

laf

GitHubioactive/laf

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

cryptographyexploitationfuzzing+5
1894 years ago
CVE-2014-4140 preview

CVE-2014-4140

GitHubday6reak/cve-2014-4140

Technical notes and debugger analysis for CVE-2014-4140, a use-after-free vulnerability in MSHTML's CHtmRootParseCtx::AddText leading to remote code…

binary-exploitationdebuggersexploitation+3
11 years ago
CVE-2019-1221 preview

CVE-2019-1221

GitHubedxsh/cve-2019-1221

Proof-of-concept exploit for CVE-2019-1221 targeting Internet Explorer 11 32-bit on Windows 10 x64 up to RS5, using VBScript.Encode and CVE-2019-0768…

exploitationpayload-generationvulnerability-analysis+1
15 years ago
Privilege-escalation-MitraStar preview

Privilege-escalation-MitraStar

GitHubleoservalli/privilege-escalation-mitrastar

Privilege escalation vulnerability on MitraStar routers

exploitationiot-securityprivilege-escalation+1
154 years ago
Kamerka-GUI preview

Kamerka-GUI

GitHubwoj-ciech/kamerka-gui

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

exploitationinformation-gatheringiot-security+6
8714 months ago
CVE-2024-4956 preview

CVE-2024-4956

GitHubverylazytech/cve-2024-4956

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal

exploitationinformation-gatheringpassword-cracking+3
161 year ago
VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS preview

VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS

GitHubmourafuseti/vulneravel-cve-2018-14847---credenciais-extraidas

VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON

exploitationiot-securitynetwork-security+3
14 months ago
Previous12…13Next