Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
284 results
springhound preview

springhound

GitHubmebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

code-analysismisconfigurationstatic-analysis+2
4 years ago
ThreatPursuit-VM preview
Archived

ThreatPursuit-VM

GitHubmandiant/threatpursuit-vm

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

curated-resourcesdigital-forensicseducation+8
1.3k3 years ago
CVE-2020-16938 preview

CVE-2020-16938

GitHubioncodes/cve-2020-16938

Bypassing NTFS permissions to read any files as unprivileged user.

data-exfiltrationexploitationforensics+2
1945 years ago
Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit preview

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

GitHub34zy/microsoft-office-word-mshtml-remote-code-execution-exploit

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

exploitationexploit-frameworkspayload-development+4
654 years ago
CVE-2017-8295 preview

CVE-2017-8295

GitHubcyberheartmi9/cve-2017-8295

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

exploitationpassword-attackspenetration-testing+3
206 years ago
refreshing-mcp-tool preview

refreshing-mcp-tool

GitHubrbowes-r7/refreshing-mcp-tool

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

database-securityexploitationinformation-gathering+5
73 years ago
CVE-2023-37250-POC preview

CVE-2023-37250-POC

GitHubewilded/cve-2023-37250-poc

Proof-of-concept exploit for CVE-2023-37250, a local privilege escalation vulnerability in Windows, with a detailed write-up explaining the roaming…

exploitationpenetration-testingprivilege-escalation+2
21 year ago
CVE-2020-0688-Python3 preview

CVE-2020-0688-Python3

GitHub1337-llama/cve-2020-0688-python3

Exploit updated to use Python 3.

exploitationpayload-generationpenetration-testing+2
22 years ago
CVE-2023-38646 preview

CVE-2023-38646

GitHubred4mber/cve-2023-38646

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection

exploitationpayload-generationpenetration-testing+2
22 years ago
alibaba__nacos_CVE-2021-44667_2-0-3 preview

alibaba__nacos_CVE-2021-44667_2-0-3

GitHubshoucheng3/alibaba__nacos_cve-2021-44667_2-0-3

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

cloud-securityexploitationmisconfiguration+3
1 year ago
QuickBox-Pro-2.1.8-Authenticated-RCE preview

QuickBox-Pro-2.1.8-Authenticated-RCE

GitHubs1gh/quickbox-pro-2.1.8-authenticated-rce

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

exploitationpenetration-testingpost-exploitation+3
6 years ago
AnonHik preview

AnonHik

GitHubanonkigroup/anonhik

Python script get image from Hikvision camera with CVE-2017-7921 vulnerability

exploitationinformation-gatheringiot-security+2
2 years ago
METABASE-RCE-CVE-2023-38646- preview

METABASE-RCE-CVE-2023-38646-

GitHubacesoyeo/metabase-rce-cve-2023-38646-

Exploit for CVE-2023-38646 in Metabase, achieving remote code execution and privilege escalation to root via unshare and setuid techniques.

exploitationpenetration-testingprivilege-escalation+2
2 years ago
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k1 day ago
CVE-2019-11932 preview

CVE-2019-11932

GitHubdorkerdevil/cve-2019-11932

double-free bug in WhatsApp exploit poc

binary-exploitationexploitationmobile-security+3
2675 years ago
CVE-2024-30051 preview

CVE-2024-30051

GitHubfortra/cve-2024-30051

Detailed technical analysis and proof-of-concept exploit for CVE-2024-30051, a heap-based buffer overflow in the Windows DWM Core Library enabling…

binary-exploitationeducationexploitation+3
1252 years ago
CVE-2020-11932 preview

CVE-2020-11932

GitHubprojectorbug/cve-2020-11932

Double-Free BUG in WhatsApp exploit poc.

binary-exploitationexploitationmobile-security+3
986 years ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
2615 days ago
Previous1…345…16Next