Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
175 results
Pollenisator preview

Pollenisator

GitHubalgosecure/pollenisator

Collaborative pentest tool with highly customizable tools

information-gatheringpenetration-testingpenetration-testing-frameworks+1
74
5 years ago
CVE-2022-22965_PoC preview

CVE-2022-22965_PoC

GitHubalt3kx/cve-2022-22965_poc

Quick pentest notes and PoC for exploiting Spring Framework RCE (CVE-2022-22965) via crafted POST requests to deploy a webshell.

educationexploitationpayload-generation+3
174 years ago
bypass-url-parser preview

bypass-url-parser

GitHublaluka/bypass-url-parser

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

information-gatheringpenetration-testingvulnerability-analysis+2
1.1k1 year ago
CVE-2023-21839-metasploit-scanner preview

CVE-2023-21839-metasploit-scanner

GitHubkw3h4/cve-2023-21839-metasploit-scanner

Metasploit auxiliary module for exploiting CVE-2023-21839 (WebLogic IIOP RCE) with DNS log verification. Automates remote code execution against…

exploit-frameworkspayload-developmentpenetration-testing+3
3 years ago
pocsploit preview

pocsploit

GitHubcckuailong/pocsploit

a lightweight, flexible and novel open source poc verification framework

exploit-frameworkspenetration-testingvulnerability-analysis+2
2374 years ago
CVE-2020-29134 preview

CVE-2020-29134

GitHubls4ss/cve-2020-29134

Shell-based exploit for CVE-2020-29134, a path traversal vulnerability in TOTVS Fluig Platform. Automates exploitation to read sensitive XML,…

exploitationinformation-gatheringpayload-generation+3
34 years ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
pwndoc preview

pwndoc

GitHubpwndoc/pwndoc

Collaborative pentest reporting application with customizable Docx templates, CVSS v3/v4 vulnerability management, multi-user real-time editing, and…

penetration-testingvulnerability-analysis
2.9k11 days ago
APTRS preview

APTRS

GitHubaptrs/aptrs

Automated pentest reporting with custom templates, project tracking, customer dashboard and client management tools. Streamline your security…

penetration-testingvulnerability-analysis
1.1k4 months ago
llm-council-vapt preview

llm-council-vapt

GitHubholiday-830/llm-council-vapt

AI-powered peer review for Pentest findings or Bug Bounty Reports — validates severity, evidence, and reporting quality before delivery using…

ai-securityeducationpenetration-testing+1
1 month ago
sploitego preview

sploitego

GitHuballfro/sploitego

Local pen-test transform package for Maltego enabling automated reconnaissance, network mapping, and vulnerability analysis through integrated tools…

exploit-frameworksinformation-gatheringnetwork-mapping+5
3956 years ago
AttackSurfaceManagement preview

AttackSurfaceManagement

GitHub1n3/attacksurfacemanagement

Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam…

exploit-frameworksinformation-gatheringosint+6
1064 years ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
739 days ago
eyeballer preview

eyeballer

GitHubbishopfox/eyeballer

Convolutional neural network for analyzing pentest screenshots

information-gatheringmachine-learningpenetration-testing+2
1.3k5 months ago
Redeye preview

Redeye

GitHubredeye-framework/redeye

Collaborative pentest data management platform for organizing servers, users, vulnerabilities, attack vectors, and files with API access and graph…

information-gatheringpenetration-testingpenetration-testing-frameworks+2
4733 years ago
laf preview

laf

GitHubioactive/laf

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

cryptographyexploitationfuzzing+5
1873 years ago
OSINT-Search preview

OSINT-Search

GitHubam0nt31r0/osint-search

Useful for digital forensics investigations or initial black-box pentest footprinting.

digital-forensicsdns-subdomain-enumerationemail-harvesting+5
1537 years ago
ferret preview

ferret

GitHubsynlace/ferret

The collaborative web app pentest suite

ai-securityapi-security-testingdynamic-analysis-sandboxing+6
571 month ago
Previous12…10Next