Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
CVE-2016-5195 preview

CVE-2016-5195

GitHubkongqbin/cve-2016-5195

Educational implementation of the Dirty COW (CVE-2016-5195) privilege escalation exploit, including race condition payload and SUID-based root shell…

binary-exploitationeducationexploitation+3
1 month ago
DHEater preview

DHEater

GitLabdheatattack/dheater

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

cryptographyexploitationnetwork-security+3
2 months ago
dheater preview

dheater

GitHubc0r0n3r/dheater

Proof-of-concept denial-of-service tool that exploits the DHEat attack (CVE-2002-20001) by enforcing Diffie-Hellman key exchange against TLS and SSH…

cryptographyexploitationnetwork-security+1
2212 months ago
CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS preview

CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS

GitHubgeorge0papasotiriou/cve-2026-11118-http-2-rapid-reset-ddos

Python PoC for CVE-2026-11118 demonstrating HTTP/2 Rapid Reset DDoS via RST_STREAM resource exhaustion; includes vulnerable server simulator and…

exploitationnetwork-securityvulnerability-analysis+1
2 months ago
HTTP-2-Rapid-Reset-DDos preview

HTTP-2-Rapid-Reset-DDos

GitHubregelepuma/http-2-rapid-reset-ddos

PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487

exploitationnetwork-securitypenetration-testing+2
8 months ago
DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint- preview

DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-

GitHubsastraadiwiguna-purpleeliteteaming/ddos-purple-teaming-offensive-multi-vector-7-tier-defensive-holistic-blueprint-

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

cloud-securitycommand-and-controldefensive-tools+9
8 months ago
CVE-2025-8671-MadeYouReset-HTTP-2-DDoS preview

CVE-2025-8671-MadeYouReset-HTTP-2-DDoS

GitHubmoften/cve-2025-8671-madeyoureset-http-2-ddos

CVE-2025-25063 MadeYouReset HTTP/2 DDoS

exploitationfuzzingpenetration-testing+2
610 months ago
CVE-2024-27686 preview

CVE-2024-27686

GitHubthemehackers/cve-2024-27686

This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to…

exploitationinformation-gatheringnetwork-security+1
31 year ago
ipeeyoupeewepee preview

ipeeyoupeewepee

GitHubpapayajackal/ipeeyoupeewepee

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

dns-analysiseducationexploitation+4
121 year ago
CVE-2023-44487 preview

CVE-2023-44487

GitHubaulauniversal/cve-2023-44487

RapidResetClient

exploitationids-ips-evasionpenetration-testing+2
11 year ago
cve-2023-44487 preview

cve-2023-44487

GitHubnxenon/cve-2023-44487

Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept

educationexploitationpayload-generation+2
152 years ago
rapidresetclient preview

rapidresetclient

GitHubsecengjeff/rapidresetclient

Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)

exploitationnetwork-securitypenetration-testing+2
762 years ago
url-regex-safe preview

url-regex-safe

GitHubspamscanner/url-regex-safe

Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661 for Node.js servers.

general-purpose-utilitiesscripting-automationstatic-analysis+2
813 years ago
DoSTool preview

DoSTool

GitHubparallelvisions/dostool

DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port.…

exploitationpenetration-testingred-teaming+1
23 years ago
callstranger-detector preview

callstranger-detector

GitHubcorelight/callstranger-detector

Zeek plugin detecting CallStranger (CVE-2020-12695) exploitation via UPnP SUBSCRIBE/NOTIFY analysis, identifying DDoS amplification, data…

data-exfiltrationdns-analysisintrusion-detection+3
63 years ago
ntpdos preview

ntpdos

GitHubsepehrdaddev/ntpdos

PoC for distributed NTP reflection DoS (CVE-2013-5211)

educationexploitationnetwork-security+1
107 years ago
sockstress preview

sockstress

GitHubmrclki/sockstress

Sockstress (CVE-2008-4609) DDoS implementation written in Go

exploitationnetwork-securitypenetration-testing+1
1710 years ago
vaas-cve-2015-5477 preview

vaas-cve-2015-5477

GitHubhmlio/vaas-cve-2015-5477

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

container-securitydns-analysiseducation+3
111 years ago