Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2213 results
ThreatScraper preview

ThreatScraper

GitHubamorath/threatscraper

Python tool that queries the VirusTotal API to check file hashes against 70+ antivirus engines, schedules recurring scans, and exports detection…

information-gatheringmalware-analysisthreat-intelligence+1
7
3 years ago
MalScan preview

MalScan

GitHubice3man543/malscan

A Simple PE File Heuristics Scanners

malware-analysisstatic-analysisvulnerability-analysis
528 years ago
below-log-race-poc preview

below-log-race-poc

GitHubdanil-koltsov/below-log-race-poc

PoC for CVE-2025-27591 – Local privilege escalation in the below monitoring tool. By symlinking its log file to /etc/passwd, an attacker can inject a…

exploitationpenetration-testingpost-exploitation+3
10 years ago
CVE-2020-25042-PoC preview

CVE-2020-25042-PoC

GitHubgroppoxx/cve-2020-25042-poc

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

exploitationpayload-developmentpenetration-testing+3
53 months ago
CVE-2019-16278_Nostromo-1.9.6---Remote-Code-Execution preview

CVE-2019-16278_Nostromo-1.9.6---Remote-Code-Execution

GitHubcybermonkx/cve-2019-16278_nostromo-1.9.6---remote-code-execution

An unauthenticated attacker can force server points to a shell file like ‘/bin/sh’ and execute arbitrary commands due to the failure in verifying the…

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2026-22200 preview

CVE-2026-22200

GitHubhorizon3ai/cve-2026-22200

CVE-2026-22200: Arbitrary file read + CNEXT RCE in osTicket

binary-exploitationexploitationpayload-generation+3
127 months ago
CVE-2019-11932-SupportApp preview

CVE-2019-11932-SupportApp

GitHubstarling021/cve-2019-11932-supportapp

Exploit helper for CVE-2019-11932 (WhatsApp GIF RCE) that calculates system() function and ROP gadget addresses for different devices to enable…

binary-exploitationexploitationmobile-security+3
6 years ago
CVE-2025-10353-POC preview

CVE-2025-10353-POC

GitHubivansmc/cve-2025-10353-poc

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

exploitationpayload-generationpenetration-testing+2
110 months ago
CVE-2019-7216 preview

CVE-2019-7216

GitHubekultek/cve-2019-7216

Filechucker filter bypass Proof Of Concept

exploitationpenetration-testingreconnaissance+2
107 years ago
log4j-remediation preview

log4j-remediation

GitHubname/log4j-remediation

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

misconfigurationsupply-chain-securityvulnerability-analysis+1
14 years ago
path-auditor preview
Archived

path-auditor

GitHubgoogle/path-auditor

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

binary-analysisdynamic-code-analysisexploitation+3
2505 years ago
log4shelldetect preview

log4shelldetect

GitHub1lann/log4shelldetect

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

code-analysismisconfigurationstatic-analysis+3
454 years ago
asclepius preview

asclepius

GitHubmatank001/asclepius

Asclepius validates backup integrity by restoring files and actively testing their recoverability. Instead of trusting metadata, it attempts to parse…

data-recoveryforensicsmalware-analysis+2
117 months ago
WebminRCE-exploit preview

WebminRCE-exploit

GitHubgokul-ramesh/webminrce-exploit

CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit

exploitationpenetration-testingprivilege-escalation+3
3 years ago
CVE-2025-53547-POC preview

CVE-2025-53547-POC

GitHubdvkunion/cve-2025-53547-poc

CVE-2025-53547 one of poc code

command-and-controlexploitationpayload-development+2
91 year ago
WiseDelete preview

WiseDelete

GitHubskimask1690/wisedelete

Windows utility that uses the vulnerable WiseDelfile64.sys driver affected by CVE-2025-66680 to enable kernel-assisted file deletion.

binary-exploitationeducationexploitation+2
122 days ago
log4j-CVE-2021-44228 preview

log4j-CVE-2021-44228

GitHubkubearmor/log4j-cve-2021-44228

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

cloud-securitycontainer-securityeducation+4
94 years ago
gitlab-12.9.0-file-read preview

gitlab-12.9.0-file-read

GitHuberk3/gitlab-12.9.0-file-read

A (wanted to be) better script than what can be found on exploit-db about the authenticated arbitrary read file on GitLab v12.9.0 (CVE-2020-10977)

exploitationinformation-gatheringpenetration-testing+2
5 years ago
Previous1234…100Next