Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
metasploitable3 preview

metasploitable3

GitHubrapid7/metasploitable3

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

dynamic-analysis-sandboxingeducationexploit-frameworks+4
5.7k
1 year ago
InfoHound preview

InfoHound

GitHubfundacio-i2cat/infohound

InfoHound is an OSINT to extract a large amount of data given a web domain name.

dns-analysiseducationemail-harvesting+8
1632 years ago
ztewaste preview

ztewaste

GitHubjoshatticus/ztewaste

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

android-securitydata-exfiltrationdigital-forensics+6
34 months ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
subcrawl preview

subcrawl

GitHubhpthreatresearch/subcrawl

Modular framework for discovering and analyzing open directories on the web. Crawls URLs, extracts content, applies YARA/ClamAV scanning, and outputs…

crawlerinformation-gatheringosint+3
1503 years ago
CVE-2024-34220 preview

CVE-2024-34220

GitHubdovankha/cve-2024-34220

Proof-of-concept exploit for CVE-2024-34220, a time-based blind SQL injection vulnerability in SourceCodester HRMS applyleave.php, with sqlmap…

exploitationinformation-gatheringpenetration-testing+2
2 years ago
sfuzz preview

sfuzz

GitHubseal9055/sfuzz

High performance fuzzing using riscv to x86 binary translations and modern fuzzing techniques

binary-analysisdynamic-analysis-sandboxingfuzzing+1
1552 years ago
CVE-2025-62821 preview

CVE-2025-62821

GitHubhyunjungg/cve-2025-62821

Microsoft HEIF Extension (msheif_store.dll) OOB-read

binary-analysisexploitationfuzzing+3
1 year ago
autofs-cve-2026-84568 preview

autofs-cve-2026-84568

GitHubjvidhan/autofs-cve-2026-84568

Reverse engineering notes and working PoC for CVE-2026-84568, a macOS automountd trust-boundary violation allowing mounts from localhost or the…

binary-analysiseducationexploitation+4
115 days ago
HLF_TxTime_spoofing preview

HLF_TxTime_spoofing

GitHubshanker-sec/hlf_txtime_spoofing

PoC covering the problem of transaction time manipulation (CVE-2024-45244) in the Hyperledger Fabric blockchain.

cryptographyeducationexploitation+1
22 years ago
CVE-2024-46532 preview

CVE-2024-46532

GitHubkamenriderdarker/cve-2024-46532

Reproduction of SQL Injection Vulnerabilities in OpenHIS

code-analysisdatabase-securityeducation+3
1 year ago
docker_cve-2015-2925 preview

docker_cve-2015-2925

GitHubkagami/docker_cve-2015-2925

Docker + CVE-2015-2925 = escaping from --volume

container-escapeexploitationpenetration-testing+3
1111 years ago