Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
223 results
ESXi-Ransomware-Scanner-mi preview

ESXi-Ransomware-Scanner-mi

GitHubcyberthreatanalysis/esxi-ransomware-scanner-mi

ESXi EZ - A custom scanner that takes list of IPs either in JSON, CSV or individually and checks for infection CVE-2021-21974

information-gatheringreconnaissancescripting-automation+2
2
3 years ago
cups-script-final-project preview

cups-script-final-project

GitHubaniruddh-bhandarkar/cups-script-final-project

Custom script to showcase the novel contribution to CVE-2025-58060

authenticationnetwork-securitypenetration-testing+3
5 months ago
POC-CVE-2025-55182 preview

POC-CVE-2025-55182

GitHubiamblacksolo2-bugbounty/poc-cve-2025-55182

Bash-based scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

educationexploitationpenetration-testing+3
9 months ago
CVE-2025-53770-Vulnerable-Scanner preview

CVE-2025-53770-Vulnerable-Scanner

GitHubimbas007/cve-2025-53770-vulnerable-scanner

Python script to scan SharePoint hosts for CVE-2025-53770 using custom payloads, with optional Burp Suite proxy interception for traffic analysis and…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
defender preview

defender

GitLab0warn/defender

This is a bash script focus on hardening linux. This is a custom think of windows defender but unlike of their privacy issue. User can feel freedom…

anomaly-detectionauthenticationconfiguration-auditing+6
6 months ago
CVE-2024-27954 preview

CVE-2024-27954

GitHubr0otk3r/cve-2024-27954

Python-based scanner for CVE-2024-27954, a Local File Inclusion vulnerability in the WordPress wp-automatic plugin. Supports multithreaded scanning,…

educationexploitationinformation-gathering+3
1 year ago
fire-wall-server preview

fire-wall-server

GitHubnosie12/fire-wall-server

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

defensive-toolseducationintrusion-detection+3
1 year ago
CVE-2019-0708-scan preview

CVE-2019-0708-scan

GitHublisinan988/cve-2019-0708-scan

Batch scanner for CVE-2019-0708 (BlueKeep) RDP vulnerability with Windows and Linux support, using rdpscan and custom Cscan for mass IP range…

exploitationinformation-gatheringnetwork-security+3
4 years ago
CVE-2025-30208-PoC preview

CVE-2025-30208-PoC

GitHubisee857/cve-2025-30208-poc

Multi-threaded Python scanner for CVE-2025-30208 Vite path traversal vulnerability with custom payload support, batch scanning, and proxy debugging.

exploitationinformation-gatheringpenetration-testing+3
1 year ago
WordList preview

WordList

GitHubrix4uni/wordlist

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

dns-subdomain-enumerationfuzzinginformation-gathering+6
1533 months ago
XXStrike preview

XXStrike

GitHubanonmoty/xxstrike

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

dynamic-code-analysisfuzzingpenetration-testing+5
314 days ago
pulsar preview
Archived

pulsar

GitHub0x0fb0/pulsar

Network footprint scanner platform. Discover domains and run your custom checks periodically.

cloud-securitydns-subdomain-enumerationinformation-gathering+6
4294 years ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
S3Scanner preview

S3Scanner

GitHubsa7mon/s3scanner

Scan for misconfigured S3 buckets across S3-compatible APIs!

cloud-securityinformation-gatheringmisconfiguration+1
3.2k2 months ago
jwt-hack preview

jwt-hack

GitHubhahwul/jwt-hack

JSON Web Token Hack Toolkit

encryption-decryption-toolspassword-crackingpayload-generation+3
1.1k2 days ago
MassBleed preview

MassBleed

GitHub1n3/massbleed

MassBleed SSL Vulnerability Scanner

network-securitypenetration-testingvulnerability-scanners
2506 years ago
faraday_plugins preview

faraday_plugins

GitHubinfobyte/faraday_plugins

Security tools report parsers for Faradaysec.com

devsecopspenetration-testingvulnerability-scanners
6225 days ago
Log4J-Scanner preview

Log4J-Scanner

GitHub0xdexter0us/log4j-scanner

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

exploitationpenetration-testingvulnerability-scanners+3
1014 years ago
Previous1234…13Next