Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
419 results
detection-tool-cve-2019-13000 preview

detection-tool-cve-2019-13000

GitHubacinq/detection-tool-cve-2019-13000

A tool that detect if your node has been victim of the invalid funding tx attack.

cryptographyforensicsincident-response+1
7 years ago
HackerLife.exe preview

HackerLife.exe

GitHubspiralbl0ck/hackerlife.exe

Write up exploit failed chain and experience tryin to sell your first nday

binary-exploitationeducationexploitation+5
1 year ago
log4j-quick-scan preview

log4j-quick-scan

GitHubmetodidavidovic/log4j-quick-scan

Scan your IP network and determine hosts with possible CVE-2021-44228 vulnerability in log4j library.

exploitationinformation-gatheringnetwork-security+3
4 years ago
CVE-2024-3400-Checker preview

CVE-2024-3400-Checker

GitHubterminaljunki3/cve-2024-3400-checker

Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.

digital-forensicsforensicsincident-response+3
2 years ago
log4shell preview

log4shell

GitHubjxerome/log4shell

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

educationexploitationlabs-practice+3
4 years ago
log4v-vuln-check preview

log4v-vuln-check

GitHubrv4l3r3/log4v-vuln-check

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).

information-gatheringlog-analysisport-scanning+3
4 years ago
cacti-rce-snmp-options-vulnerable-application preview

cacti-rce-snmp-options-vulnerable-application

GitHubm3ssap0/cacti-rce-snmp-options-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!

command-and-controleducationexploitation+3
1 year ago
CVE-2023-23583-Reptar- preview

CVE-2023-23583-Reptar-

GitHubmav3r1ck0x1/cve-2023-23583-reptar-

This script can help determine the CPU ID for the processor of your system, please note that I have not added every CPU ID to this script, edit as…

binary-analysisexploitationhardware-security+2
2 years ago
springhound preview

springhound

GitHubmebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

code-analysismisconfigurationstatic-analysis+2
4 years ago
CVE-2024-3094-Checker preview

CVE-2024-3094-Checker

GitHubthetorjancaptain/cve-2024-3094-checker

The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.

configuration-auditinggeneral-purpose-utilitiesscripting-automation+2
2 years ago
regreSSHion-CVE-2024-6387- preview

regreSSHion-CVE-2024-6387-

GitHubinvaderslabs/regresshion-cve-2024-6387-

Provides instructions for using the script to check if your OpenSSH installation is vulnerable to CVE-2024-6387

configuration-auditingexploitationinformation-gathering+3
2 years ago
CVE-2013-3900_Remediation_PowerShell preview

CVE-2013-3900_Remediation_PowerShell

GitHubpiranhap/cve-2013-3900_remediation_powershell

Script to make changes on registry to fix CVE-2013-3900. It comes with an option to undo in case it breaks something on your environment.

configuration-auditinggeneral-purpose-utilitiesmisconfiguration+1
1 year ago
Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467- preview

Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-

GitHubahmedmansour93/event-id-217-rule-name-soc254-apache-ofbiz-auth-bypass-and-code-injection-0day-cve-2023-51467-

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

educationexploitationincident-response+3
2 years ago
wordpress-cve-scanner preview

wordpress-cve-scanner

GitLabvaltersit/wordpress-cve-scanner

Scan your WordPress core, themes and plugins for known CVEs from the command line. Open source, auditable, privacy-first — powered by the ValtersIT…

configuration-auditingdevsecopsvulnerability-analysis+3
3 days ago
VulnWhisperer preview
Archived

VulnWhisperer

GitHubhasecuritysolutions/vulnwhisperer

Create actionable data from your Vulnerability Scans

configuration-auditingdevsecopslog-analysis+3
1.4k4 months ago
CVE-2020-1350 preview
Archived

CVE-2020-1350

GitHubt13nn3s/cve-2020-1350

This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service

dns-analysisexploitationpenetration-testing+2
153 years ago
AuraBorealisApp preview
Archived

AuraBorealisApp

GitHubiqtlabs/auraborealisapp

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

code-analysismalware-analysisstatic-code-analysis+2
204 years ago
bidi_char_detector preview
Archived

bidi_char_detector

GitHubmaweil/bidi_char_detector

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

code-analysismisconfigurationsecret-detection+3
63 years ago
Previous1…678…24Next