Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
ApacheTomcatScanner preview

ApacheTomcatScanner

GitHubp0dalirius/apachetomcatscanner

A python script to scan for Apache Tomcat server vulnerabilities.

information-gatheringvulnerability-analysisvulnerability-scanners+1
892
8 months ago
log4shell preview

log4shell

GitHubhozyx/log4shell

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

code-analysisdevsecopsstatic-analysis+3
4 years ago
project_BIT_nmap_script preview

project_BIT_nmap_script

GitHubmgregus/project_bit_nmap_script

Nmap .nse script to scan for CVE-2022-32073 in wolfssh

exploitationinformation-gatheringnetwork-security+3
33 years ago
python-patrol preview

python-patrol

GitHubcodeskipper/python-patrol

Scan for python installations on macOS, and run CVE-2015-20107.py script to report if patching is needed

general-purpose-utilitiesscripting-automationvulnerability-analysis+1
2 years ago
React2Shell-Vulnerability-Verification-Script preview

React2Shell-Vulnerability-Verification-Script

GitHubdegenwithheart/react2shell-vulnerability-verification-script

Standalone Python script to verify if a project is affected by CVE-2025-55182 (React2Shell). Checks package.json dependencies and performs optional…

code-analysiseducationstatic-analysis+3
9 months ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubxfreed0m/cve-2018-10933

a python script to exploit libssh authentication vulnerability

educationexploitationnetwork-security+2
36 years ago
log4j-cve-2021-44228 preview

log4j-cve-2021-44228

GitHublucab85/log4j-cve-2021-44228

Ansible playbook automating Red Hat's Log4j detector script to scan Linux hosts for CVE-2021-44228 (Log4Shell) vulnerability with GPG verification.

cloud-securityconfiguration-auditingdevsecops+3
574 years ago
PySCTChecker preview

PySCTChecker

GitHubelevenpaths/pysctchecker

Python script to verify Certificate Transparency (SCT) implementation in domains by checking embedded, TLS extension, and OCSP-stapled SCTs,…

information-gatheringvulnerability-analysis
29 years ago
CVE-2020-3452-PoC preview

CVE-2020-3452-PoC

GitHubxdev05/cve-2020-3452-poc

Automates downloading and running an Nmap NSE script to scan hosts for CVE-2020-3452 vulnerability, using a list of target hosts.

exploitationpenetration-testingreconnaissance+3
26 years ago
log4j-finder preview

log4j-finder

GitHubfox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

code-analysisincident-responsestatic-analysis+3
4393 years ago
log4j-fix-CVE-2021-44228 preview

log4j-fix-CVE-2021-44228

GitHubchandru-gunasekaran/log4j-fix-cve-2021-44228

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

general-purpose-utilitiesmisconfigurationscripting-automation+2
24 years ago
log4j-scanner preview

log4j-scanner

GitHubcodiobert/log4j-scanner

Lightweight bash script to quickly scan systems for the Log4j CVE-2021-44228 vulnerability via a one-liner command.

exploitationgeneral-purpose-utilitiesscripting-automation+2
34 years ago
CVE-2024-4956 preview

CVE-2024-4956

GitHubgoatsecurity/cve-2024-4956

CVE-2024-4956 : Nexus Repository Manager 3 poc exploit

exploitationinformation-gatheringpenetration-testing+3
32 years ago
ipsourcebypass preview

ipsourcebypass

GitHubp0dalirius/ipsourcebypass

This Python script can be used to bypass IP source restrictions using HTTP headers.

information-gatheringpenetration-testingvulnerability-analysis+1
4061 year ago
Joomla3.7-SQLi-CVE-2017-8917 preview

Joomla3.7-SQLi-CVE-2017-8917

GitHubbrianwrf/joomla3.7-sqli-cve-2017-8917

Joomla 3.7 SQL injection (CVE-2017-8917)

exploitationinformation-gatheringreconnaissance+2
79 years ago
CVE-2019-15107-RCE-WebMin preview

CVE-2019-15107-RCE-WebMin

GitHubedouardosstav/cve-2019-15107-rce-webmin

Lightweight Python script that fingerprints Webmin versions and flags servers running 1.882 ≤ version ≤ 1.920 as potentially vulnerable to…

information-gatheringpenetration-testingreconnaissance+3
1 year ago
Inspector preview

Inspector

GitHubgraniet/inspector

The Inspector tool is a privilege escalation helper (PoC), easy to deployed on web server, this tool can list process running with root, check kernel…

information-gatheringpenetration-testingprivilege-escalation+1
1207 years ago
ssh_user_enum preview

ssh_user_enum

GitHubnccgroup/ssh_user_enum

SSH User Enumeration Script in Python Using The Timing Attack

information-gatheringpenetration-testingreconnaissance+1
9510 years ago
Previous12Next