Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
419 results
CVE-2023-36874 preview

CVE-2023-36874

GitHubwh04m1001/cve-2023-36874

Proof-of-concept exploit for CVE-2023-36874, a Windows elevation of privilege vulnerability. Demonstrates exploitation on vulnerable Windows clients…

binary-exploitationexploitationpenetration-testing+2
243
3 years ago
versionscan preview

versionscan

GitHubpsecio/versionscan

A PHP version scanner for reporting possible vulnerabilities

vulnerability-analysisvulnerability-scanners
2486 years ago
laf preview

laf

GitHubioactive/laf

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

cryptographyexploitationfuzzing+5
1894 years ago
GitHound preview

GitHound

GitHubspecterops/githound

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

cloud-securityidentity-access-managementinformation-gathering+4
1471 month ago
Bughound preview

Bughound

GitHubmhaskar/bughound

Static code analysis tool based on Elasticsearch

code-analysisdevsecopsstatic-code-analysis+2
1305 years ago
findyara-ida preview

findyara-ida

GitHuboalabs/findyara-ida

IDA python plugin to scan binary with Yara rules

binary-analysismalware-analysisreverse-engineering+2
1844 years ago
BFuzz preview

BFuzz

GitHubrootup/bfuzz

Fuzzing Browsers

fuzzingvulnerability-analysisweb-security
3183 years ago
CVE-2024-38063-poc preview

CVE-2024-38063-poc

GitHubsachinart/cve-2024-38063-poc

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

binary-exploitationeducationexploitation+3
862 years ago
GOATCasino preview

GOATCasino

GitHubnccgroup/goatcasino

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

code-analysisctfeducation+3
1207 years ago
autonomous-offensive-llm-handbook preview

autonomous-offensive-llm-handbook

GitHubmouteee/autonomous-offensive-llm-handbook

A deterministic harness and handbook for autonomous offensive LLM agents, enforcing authorization, scope, and evidence gates to ensure reproducible…

ai-securitycurated-resourceseducation+4
703 days ago
jira-mobile-ssrf-exploit preview

jira-mobile-ssrf-exploit

GitHubassetnote/jira-mobile-ssrf-exploit

Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)

exploitationinformation-gatheringpenetration-testing+3
854 years ago
fortiscan preview

fortiscan

GitHubanasbousselham/fortiscan

A high performance FortiGate SSL-VPN vulnerability scanning and exploitation tool.

exploitationpenetration-testingvulnerability-analysis+1
1603 years ago
cve-2013-2094 preview

cve-2013-2094

GitHubrealtalk/cve-2013-2094

original cve-2013-2094 exploit and a rewritten version for educational purposes

binary-exploitationeducationexploitation+2
9113 years ago
InfoHound preview

InfoHound

GitHubfundacio-i2cat/infohound

InfoHound is an OSINT to extract a large amount of data given a web domain name.

dns-analysiseducationemail-harvesting+8
1632 years ago
Fortijump-Exploit-CVE-2024-47575 preview

Fortijump-Exploit-CVE-2024-47575

GitHubwatchtowrlabs/fortijump-exploit-cve-2024-47575

Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

exploitationpenetration-testingred-teaming+3
971 year ago
open-sammy preview

open-sammy

GitHubowasp/open-sammy

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

cloud-securityconfiguration-auditingcontainer-security+3
2920 days ago
c-sentinel preview

c-sentinel

GitHubspeytech/c-sentinel

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

ai-securityanomaly-detectionauthentication+8
726 months ago
h3-cli preview

h3-cli

GitHubhorizon3ai/h3-cli

CLI tool for the Horizon3.ai API

cloud-securitydevsecopspenetration-testing-frameworks+3
254 days ago
Previous1…91011…24Next