Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
206 results
OllamaHound preview

OllamaHound

GitHub7h30th3r0n3/ollamahound

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

command-and-controlexploitationinformation-gathering+6
62
7 months ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

ai-securitycommand-and-controldata-exfiltration+7
3703 months ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
cpanel-cve-2026-41940-fix preview

cpanel-cve-2026-41940-fix

GitHubshahidmallaofficial/cpanel-cve-2026-41940-fix

One-shot detection and remediation for cPanel/WHM servers compromised via CVE-2026-41940, including IOC checks, malware cleanup, C2 blocking, and…

cloud-infrastructure-securityconfiguration-auditingdigital-forensics+5
54 months ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

anomaly-detectiondigital-forensicsdisk-forensics+11
3.8k8 months ago
cpanel-cve-41940-detector preview

cpanel-cve-41940-detector

GitHublimo57640-crypto/cpanel-cve-41940-detector

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

digital-forensicsforensicsincident-response+6
2 months ago
tanstack-compromise-checker preview

tanstack-compromise-checker

GitHubry-allan/tanstack-compromise-checker

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

command-and-controlforensicsincident-response+6
3 months ago
CyberStrikeAI preview

CyberStrikeAI

GitHubed1s0nz/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+9
6.5k1 day ago
kubesploit preview

kubesploit

GitHubcyberark/kubesploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

command-and-controlcontainer-escapecontainer-security+8
1.2k1 year ago
Vulnerability-Disclosures preview

Vulnerability-Disclosures

GitHubmandiant/vulnerability-disclosures

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

exploitationpenetration-testingred-teaming+3
22221 days ago
killchain preview

killchain

GitHubruped24/killchain

A unified console to perform the "kill chain" stages of attacks.

command-and-controlexploit-frameworkspayload-generation+5
2083 years ago
DblTekGoIPPwn preview

DblTekGoIPPwn

GitHubjacobmisirian/dbltekgoippwn

Tool to check if an IP of a DblTek GoIP is vulnerable to a challenge-response login system, send SMS messages from the system, execute remote…

command-and-controlexploitationpenetration-testing+2
646 years ago
strutsy preview

strutsy

GitHubtahmed11/strutsy

Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability

command-and-controlexploitationinformation-gathering+3
108 years ago
CVE-2023-22527 preview

CVE-2023-22527

GitHubrevoltsecurities/cve-2023-22527

Exploitation tool for CVE-2023-22527 targeting Confluence servers, enabling remote code execution with support for multiple targets, concurrency, and…

exploitationpenetration-testingred-teaming+3
102 years ago
CVE-2025-24016-Nuclei-Template preview

CVE-2025-24016-Nuclei-Template

GitHubhuseyinstif/cve-2025-24016-nuclei-template

Nuclei template to detect CVE-2025-24016 unsafe deserialization RCE in Wazuh servers via a crafted JSON payload that triggers a NameError.

code-analysisexploitationpenetration-testing+3
41 year ago
CVE-2026-21962 preview

CVE-2026-21962

GitHubthumpbo/cve-2026-21962

Exploit script for CVE-2026-21962, enabling remote command execution on vulnerable web servers with single-target, batch, and reverse shell modes.

command-and-controlexploitationpenetration-testing+2
27 months ago
cve-2024-6387-nuclei-template preview

cve-2024-6387-nuclei-template

GitHubbrandonlynch2402/cve-2024-6387-nuclei-template

Nuclei template to detect OpenSSH servers vulnerable to CVE-2024-6387 (regreSSHion) by checking software version.

exploitationpenetration-testingred-teaming+3
32 years ago
CVE-2025-55182-Waf preview

CVE-2025-55182-Waf

GitHubl0n3m4n/cve-2025-55182-waf

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

command-and-controlexploitationpayload-generation+5
28 months ago
Previous12…12Next