Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
247 results
Oihk-pentesting preview

Oihk-pentesting

GitHubbroskigx/oihk-pentesting

Autonomous multi-agent AI penetration-testing engine: a governed tool sandbox, an immutable evidence-and-validation gate, and a reproducible…

ai-securityeducationexploit-frameworks+7
4
4 days ago
osiris preview

osiris

GitHubsimplifaisoul/osiris

Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative - …

dns-analysisinformation-gatheringnetwork-mapping+7
9.8k4 days ago
CVE-2026-41089-Netlogon-RCE-PoC preview

CVE-2026-41089-Netlogon-RCE-PoC

GitHubgillarchnganasan2735/cve-2026-41089-netlogon-rce-poc

Automate Netlogon CVE-2026-41089 validation and defensive testing through integrated AI security workflows, enabling rapid risk assessment and…

defensive-toolseducationexploitation+5
3 days ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubyasouxken/cve-2026-41940-poc

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

authenticationcommand-and-controlexploitation+7
3 days ago
OpenHunterAI preview

OpenHunterAI

GitHublumoslab-innovation/openhunterai

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

ai-securityapi-securityapi-security-testing+9
32410 days ago
KUMO-Domain-Recon-Tool preview

KUMO-Domain-Recon-Tool

GitHubkarim852/kumo-domain-recon-tool

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

dns-analysisinformation-gatheringosint+8
486 days ago
CVE-2026-42031-SQL-Injection-Scanner preview

CVE-2026-42031-SQL-Injection-Scanner

GitHubddrvahandzo90-hue/cve-2026-42031-sql-injection-scanner

Automated SQL injection scanner for CKAN DataStore, detecting and validating CVE-2026-42031 with multi-target scanning, data dumping, and report…

database-securityexploitationinformation-gathering+3
118 days ago
CVE-2026-41940 preview

CVE-2026-41940

GitHub0xgh057r3c0n/cve-2026-41940

cPanel & WHM - Authentication Bypass via Session-File CRLF Injection

authentication-authorizationexploitationpenetration-testing+4
120 days ago
CVE-2026-65643-PoC-Toolkit preview

CVE-2026-65643-PoC-Toolkit

GitHubtc4dy/cve-2026-65643-poc-toolkit

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

command-and-controlexploitationpayload-development+7
1220 days ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
27 days ago
CVE-2026-23918-Elite-Auditor preview

CVE-2026-23918-Elite-Auditor

GitHubqassam-315/cve-2026-23918-elite-auditor

Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and…

information-gatheringpenetration-testingreconnaissance+3
64 months ago
cPanel-CVE-2026-41940-Scanner preview

cPanel-CVE-2026-41940-Scanner

GitHubmerdw/cpanel-cve-2026-41940-scanner

Advanced cPanel & WHM Security Scanner for CVE-2026-41940. with mass Shodan discovery

exploitationinformation-gatheringpenetration-testing+3
34 months ago
log4j-fuzzer preview

log4j-fuzzer

GitHubmr-vill4in/log4j-fuzzer

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.

exploitationfuzzingpenetration-testing+2
34 years ago
NoPacScan preview

NoPacScan

GitHubknightswd/nopacscan

Scans Active Directory domain controllers for CVE-2021-42287 and CVE-2021-42278 by querying DNS for all DCs and analyzing PAC structures for the 0x10…

authenticationexploitationnetwork-security+2
874 years ago
Mass-CVE-2026-23550-Exploit preview

Mass-CVE-2026-23550-Exploit

GitHubdzmind2312/mass-cve-2026-23550-exploit

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

exploitationinformation-gatheringpenetration-testing+3
27 months ago
detect_CVE-2026-25177 preview

detect_CVE-2026-25177

GitHubdanaug23/detect_cve-2026-25177

Production-safe scanner that detects CVE-2026-25177 (AD SPN Unicode Collision) exploitation on Active Directory Domain Controllers. Read-only.

configuration-auditingvulnerability-scanners
46 months ago
PS-CVE-2021-44228 preview

PS-CVE-2021-44228

GitHubarnaudluti/ps-cve-2021-44228

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
4 years ago
CVE-2024-6387_PoC preview

CVE-2024-6387_PoC

GitHubyassdev221608/cve-2024-6387_poc

Scans and exploits CVE-2024-6387 (regreSSHion) in OpenSSH servers. Features multi-threaded scanning, banner retrieval, grace time detection, and…

exploitationnetwork-securitypenetration-testing+2
161 year ago
Previous12…14Next