Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
124 results
web-penetration-drupal preview

web-penetration-drupal

GitHuberman-bolukbasi/web-penetration-drupal

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

exploit-frameworkspenetration-testingreconnaissance+3
2 months ago
internal-penetration-testing-project-using-Metasploit preview

internal-penetration-testing-project-using-Metasploit

GitHubabdullah50i/internal-penetration-testing-project-using-metasploit

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

exploitationexploit-frameworksinformation-gathering+6
1 month ago
CVE-2013-1081 preview

CVE-2013-1081

GitHubsteponequit/cve-2013-1081

Novell ZENworks Mobile Management - LFI RCE

exploitationexploit-frameworkspayload-development+3
213 years ago
CVE-2016-5639 preview

CVE-2016-5639

GitHubxfox64x/cve-2016-5639

Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules

exploitationexploit-frameworksinformation-gathering+3
26 years ago
WordPress_Backup_Migration-RCE_Unauthenticated preview

WordPress_Backup_Migration-RCE_Unauthenticated

GitHubjoaoaugustom/wordpress_backup_migration-rce_unauthenticated

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

command-and-controlexploit-frameworkspayload-development+3
26 days ago
metasploit-framework-nu11secur1ty preview

metasploit-framework-nu11secur1ty

GitHubnu11secur1ty/metasploit-framework-nu11secur1ty

Extending of metasploit-framework

command-and-controlexploitationexploit-frameworks+9
111 months ago
Samba-Exploit-CVE-2007-2447 preview

Samba-Exploit-CVE-2007-2447

GitHubnulltrace1336/samba-exploit-cve-2007-2447

Step-by-step guide to exploiting Samba 3.0.20 (CVE-2007-2447) using Metasploit, including Nmap scanning, payload setup, and reverse shell execution.

command-and-controlexploitationexploit-frameworks+3
8 months ago
Blackash-CVE-2025-24071 preview

Blackash-CVE-2025-24071

GitHubzbs54/blackash-cve-2025-24071

CVE-2025-24071

exploitationexploit-frameworksinformation-gathering+3
1 year ago
PrintNightmare-CVE-2021-1675-CVE-2021-34527 preview

PrintNightmare-CVE-2021-1675-CVE-2021-34527

GitHubgaloget/printnightmare-cve-2021-1675-cve-2021-34527

CVE-2021-1675 / CVE-2021-34527 - PrintNightmare Python, C# and PowerShell Exploits Implementations (LPE & RCE)

exploitationexploit-frameworkslateral-movement+5
5 years ago
CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784 preview

CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784

GitHubhirusha-n/cve-2021-34527-cve-2023-38831-and-cve-2023-32784
exploitationexploit-frameworkspayload-development+3
2 years ago
exploitdb preview
Archived

exploitdb

GitHuboffensive-security/exploitdb

The legacy Exploit Database repository - New repo located at https://gitlab.com/exploit-database/exploitdb

exploitationexploit-frameworksinformation-gathering+3
7.9k3 years ago
vFeed preview
Archived

vFeed

GitHubtoolswatch/vfeed

The Correlated CVE Vulnerability And Threat Intelligence Database API

exploit-frameworksinformation-gatheringpenetration-testing+3
9475 years ago
aws-doctor preview

aws-doctor

GitHubelc0mpa/aws-doctor

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
42914 days ago
ai-llm-red-team-handbook preview

ai-llm-red-team-handbook

GitHubshiva108/ai-llm-red-team-handbook

AI / LLM Red Team Field Manual & Consultant’s Handbook

adversarial-attackai-securityeducation+6
3323 months ago
POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0 preview

POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0

GitHubheavyghost-le/poc_sql_injection_in_parse_server_prior_6.5.7_-_7.1.0

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

database-securityexploitationinformation-gathering+3
111 months ago
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

cloud-securitycurated-resourceseducation+8
352 months ago
sparkplugFuzzer preview

sparkplugFuzzer

GitHubbishopfox/sparkplugfuzzer

Fuzzer for the Sparkplug B IIoT protocol

authenticationdynamic-analysis-sandboxingfuzzing+5
11 month ago
trivy preview

trivy

GitHubaquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

cloud-infrastructure-securitycloud-securitycode-analysis+14
37.8k2 days ago
Previous1234567Next