Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
75 results
CVE-2025-23048-POC preview

CVE-2025-23048-POC

GitHubabsholi7ly/cve-2025-23048-poc

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

authenticationexploitationpenetration-testing+3
4
10 months ago
recog preview

recog

GitHubrapid7/recog

Pattern recognition for hosts, services, and content

information-gatheringnetwork-mappingosint+4
7894 days ago
laf preview
Archived

laf

GitHubtakeshixx/laf

Login Area Finder: scans host/s for login panels

information-gatheringpenetration-testingreconnaissance+2
1411 years ago
ipeeyoupeewepee preview

ipeeyoupeewepee

GitHubpapayajackal/ipeeyoupeewepee

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

dns-analysiseducationexploitation+4
111 year ago
XnlReveal preview

XnlReveal

GitHubxnl-h4ck3r/xnlreveal

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

information-gatheringosintpenetration-testing+3
4523 months ago
cve-2019-0708 preview

cve-2019-0708

GitHubmekhalleh/cve-2019-0708

Metasploit module for massive Denial of Service using #Bluekeep vector.

exploitationexploit-frameworkspenetration-testing+1
236 years ago
hostscan preview

hostscan

GitHubsmaash/hostscan

php tool for network scanning

crawlerinformation-gatheringnetwork-mapping+5
2011 years ago
LiveTargetsFinder preview

LiveTargetsFinder

GitHuballyomalley/livetargetsfinder

Generates lists of live hosts and URLs for targeting, automating the usage of MassDNS, Masscan and nmap to filter out unreachable hosts and gather…

dns-analysisinformation-gatheringnetwork-mapping+3
3676 years ago
gssapi-abuse preview

gssapi-abuse

GitHubccob/gssapi-abuse

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

authenticationdns-analysisinformation-gathering+5
1881 year ago
exploits preview

exploits

GitHubtecr0c/exploits

This repository hosts PoC exploits for vulnerabilities I've discovered, provided for education and to highlight the importance of system security.

educationexploitationpenetration-testing+1
193 years ago
CVE-2024-30052 preview

CVE-2024-30052

GitHubynwarcs/cve-2024-30052

Materials for CVE-2024-30052.

binary-exploitationdebuggerseducation+3
121 year ago
CVE-2025-34028-PoC-Commvault-RCE preview

CVE-2025-34028-PoC-Commvault-RCE

GitHubmattb709/cve-2025-34028-poc-commvault-rce

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…

exploitationpenetration-testingred-teaming+3
21 year ago
sast-rules preview

sast-rules

GitLabgitlab-org/security-products/sast-rules

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

code-analysisdevsecopseducation+2
297 days ago
CVE-2025-29306-PoC-FoxCMS-RCE preview

CVE-2025-29306-PoC-FoxCMS-RCE

GitHubmattb709/cve-2025-29306-poc-foxcms-rce

Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets,…

educationexploitationpenetration-testing+3
51 year ago
log4shell-docker-lab preview

log4shell-docker-lab

GitHubaxelcurmi/log4shell-docker-lab

Log4Shell (CVE-2021-44228) docker lab

container-securityeducationexploitation+3
4 years ago
svg-cheatsheet preview

svg-cheatsheet

GitHuballanlw/svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

curated-resourceseducationinformation-gathering+4
8026 years ago
CVE-2024-3273 preview

CVE-2024-3273

GitHubadhikara13/cve-2024-3273

Exploit for CVE-2024-3273, supports single and multiple hosts

command-and-controlexploitationpenetration-testing+3
132 years ago
watchtowr-vs-telnetd-CVE-2026-32746 preview

watchtowr-vs-telnetd-CVE-2026-32746

GitHubwatchtowrlabs/watchtowr-vs-telnetd-cve-2026-32746

Detection script for telnetd CVE-2026-32746 that probes remote hosts to identify vulnerable LINEMODE support via TCP connection, generating detection…

network-securitypenetration-testingreconnaissance+2
115 months ago
Previous12345Next