Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
319 results
LALIN preview
Archived

LALIN

GitHubscreetsec/lalin

this script automatically install any package for pentest with uptodate tools , and lazy command for run the tools like lazynmap , install another…

information-gatheringpenetration-testingreconnaissance+3
3819 years ago
react2shell-scanner preview

react2shell-scanner

GitHubhidden-investigations/react2shell-scanner

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

educationexploitationpenetration-testing+3
57 months ago
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
28.3k11h 11m ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5334 years ago
CVE-2015-1635 preview

CVE-2015-1635

GitHubcappricio-securities/cve-2015-1635

Microsoft Windows 'HTTP.sys' - Remote Code Execution

exploitationinformation-gatheringpenetration-testing+3
12 years ago
testssl.sh preview

testssl.sh

GitHubtestssl/testssl.sh

Testing TLS/SSL encryption anywhere on any port

cryptographynetwork-securitypenetration-testing+2
9.2k2 days ago
strutsy preview

strutsy

GitHubtahmed11/strutsy

Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability

command-and-controlexploitationinformation-gathering+3
108 years ago
portscan-CVE-2026-41940 preview

portscan-CVE-2026-41940

GitHubamirrezamarzban/portscan-cve-2026-41940

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

information-gatheringnetwork-securitypenetration-testing+3
15 months ago
PHP_8.1.x_Exploit preview

PHP_8.1.x_Exploit

GitHubgl1tch0x1/php_8.1.x_exploit

Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)

command-and-controlcrawlerexploitation+7
15 months ago
React2Shell preview

React2Shell

GitHubprowlsec/react2shell

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

command-and-controlexploitationpayload-generation+4
19 months ago
shennina preview

shennina

GitHubmazen160/shennina

Automating Host Exploitation with AI

ai-securitycommand-and-controldata-exfiltration+5
5563 years ago
fubucker preview

fubucker

GitHubim-hanzou/fubucker

Automatic Mass Tool for checking vulnerability in CVE-2022-1386 - Fusion Builder < 3.6.2 - Unauthenticated SSRF

exploitationinformation-gatheringpenetration-testing+3
63 years ago
CVE-2026-82222 preview

CVE-2026-82222

GitHubghostlyrootb2h/cve-2026-82222

Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

command-and-controlexploitationinformation-gathering+5
27 days ago
r2s preview

r2s

GitHubzamdevio/r2s

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

command-and-controlexploitationinformation-gathering+5
210 months ago
CVE-2022-30525_check preview

CVE-2022-30525_check

GitHubcbk914/cve-2022-30525_check

Python script to detect CVE-2022-30525 OS command injection vulnerability in Zyxel USG FLEX devices by sending crafted HTTP requests and analyzing…

command-and-controlexploitationpenetration-testing+2
23 years ago
faraday_plugins preview

faraday_plugins

GitHubinfobyte/faraday_plugins

Security tools report parsers for Faradaysec.com

devsecopspenetration-testingvulnerability-scanners
621 month ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12613 years ago
Dracnmap preview

Dracnmap

GitHubscreetsec/dracnmap

Dracnmap is an open source program which is using to exploit the network and gathering information with nmap help. Nmap command comes with lots of…

information-gatheringnetwork-mappingpenetration-testing+2
1.4k8 years ago
Previous12…18Next