Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
Startup-SBOM preview

Startup-SBOM

GitHubmorpheuslord/startup-sbom

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

cloud-securityconfiguration-auditingcontainer-security+4
17
5 months ago
LFISuite preview

LFISuite

GitHubd35m0nd142/lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

exploitationpayload-generationpenetration-testing+3
2.0k8 years ago
melee preview

melee

GitHubadityaks/melee

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

database-securityincident-responsemalware-analysis+2
233 years ago
qualcomm-vulnerability-scanner preview

qualcomm-vulnerability-scanner

GitHubdarkz2012/qualcomm-vulnerability-scanner

A tool to scan Android devices for the recently exploited Qualcomm flaw CVE-2026-21385, providing a simple and efficient way to identify vulnerable…

android-securitymobile-securityvulnerability-scanners
16 months ago
IkeAbuser preview

IkeAbuser

GitHubrandomuser1983/ikeabuser

A simple tool wrapper to automate the enumeration, fingerprinting, and PSK extraction of an IPSec VPN gateway.

ctfeducationinformation-gathering+5
32 months ago
CertVerify preview

CertVerify

GitHubpassword123456/certverify

A scanner that files with compromised or untrusted code signing certificates written in python.

code-analysisforensicsmalware-analysis+1
653 years ago
BlueborneDetection preview

BlueborneDetection

GitHubmjancek/bluebornedetection

Simple detection tool for Blueborne vulnerability found on Android devices --- CVE-2017-0781.

android-securitybluetooth-securityexploitation+2
15 years ago
DroidSniper preview

DroidSniper

GitHubk3ystr0k3r/droidsniper

DroidSniper - Misconfigured Android Debug Bridge Scanner

android-securitymisconfigurationpenetration-testing+2
172 years ago
Robber preview

Robber

GitHubmojtabatajik/robber

Robber is open source tool for finding executables prone to DLL hijacking

binary-analysisprivilege-escalationvulnerability-analysis+1
7994 months ago
Fast-CVE-2022-22965 preview

Fast-CVE-2022-22965

GitHubiloveflag/fast-cve-2022-22965

Graphical detection tool for CVE-2022-22965 (Spring4Shell) with one-click reverse shell generation, command execution, and multi-server shell path…

command-and-controlexploitationpayload-generation+3
43 years ago
kit_hunter preview

kit_hunter

GitHubsteved3/kit_hunter

A basic phishing kit scanner for dedicated and semi-dedicated hosting

malware-analysisphishing-toolsvulnerability-scanners+1
1093 years ago
siofra preview

siofra

GitHubcybereason/siofra

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

binary-analysisbinary-exploitationpayload-generation+4
5138 years ago
CVE-2026-73296 preview

CVE-2026-73296

GitHub0xblackash/cve-2026-73296

Non-destructive security assessment tool for CVE-2026-73296, checking authentication boundaries on exposed Mobile MCP HTTP servers (ports 8020/8021)…

android-securityexploitationiot-security+3
19 days ago
Mass-exploit-CVE-2022-29464 preview

Mass-exploit-CVE-2022-29464

GitHubhxlxmj/mass-exploit-cve-2022-29464

Mass exploitation tool for CVE-2022-29464 targeting WSO2 Carbon Server. Automates pre-auth RCE scanning via Shodan/ZoomEye, uploads webshells and…

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubluoqichen/cve-2025-55182-poc

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

command-and-controlexploitationpayload-development+5
6 months ago
tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228 preview

tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228

GitHubtharindudh/tharindudh-log4j-vulnerability-in-ghidra-tool-cve-2021-44228

Ghidra-based tool for detecting and analyzing the Log4j vulnerability (CVE-2021-44228) in binary files, enabling reverse engineering of affected…

binary-analysisexploitationreverse-engineering+3
4 years ago
CVE-2024-6387_PoC preview

CVE-2024-6387_PoC

GitHubyassdev221608/cve-2024-6387_poc

Scans and exploits CVE-2024-6387 (regreSSHion) in OpenSSH servers. Features multi-threaded scanning, banner retrieval, grace time detection, and…

exploitationnetwork-securitypenetration-testing+2
171 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcarlosaruy/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

ctfeducationexploitation+6
9 months ago
Previous12Next