Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources and tools

cloud-securityctfcurated-resources+10
27.3k
2 months ago
easy-exploits preview

easy-exploits

GitHubefchatz/easy-exploits

Curated collection of proof-of-concept exploits for 16 CVEs targeting web applications (ASUS, D-Link, Netgear, TP-Link, Xiaomi) and Wi-Fi WPA3-SAE,…

educationexploitationpenetration-testing+3
173 years ago
js2py-Sandbox-Escape-CVE-2024-28397-RCE preview

js2py-Sandbox-Escape-CVE-2024-28397-RCE

GitHub0xdtc/js2py-sandbox-escape-cve-2024-28397-rce

Exploit scripts for CVE-2024-28397, a js2py sandbox escape that executes arbitrary Python code to spawn a reverse shell on a target endpoint.

educationexploitationpayload-generation+3
1 year ago
wordpress-hacking preview

wordpress-hacking

GitHubstealthcopter/wordpress-hacking

A collection of useful resources for hacking WordPress and it's plugins and themes

curated-resourcesdynamic-code-analysisexploitation+4
896 months ago
tbhm preview

tbhm

GitHubjhaddix/tbhm

The Bug Hunters Methodology

curated-resourceseducationlearning-paths-courses+4
4.4k3 years ago
Shockwave-OSS preview

Shockwave-OSS

GitHubgal-nagli/shockwave-oss

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

curated-resourceseducationfuzzing+9
7512 years ago
ai-exploits preview

ai-exploits

GitHubprotectai/ai-exploits

A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities

ai-securitycurated-resourceseducation+4
1.7k1 year ago
vulnerable-mcp-servers-lab preview

vulnerable-mcp-servers-lab

GitHubappsecco/vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

ai-securitycode-analysiseducation+7
2759 months ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5522 years ago
joomla_exploits preview

joomla_exploits

GitHubaramosf/joomla_exploits

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

crawlereducationexploitation+5
12 months ago
CVEs preview

CVEs

GitHubburaksevben/cves

Curated collection of proof-of-concept exploits for web vulnerabilities including cross-site scripting and SQL injection, with detailed technical…

curated-resourcesexploitationpapers-research+2
102 years ago
awesome-websocket-security preview

awesome-websocket-security

GitHubpalindromelabs/awesome-websocket-security

Awesome information for WebSockets security research

curated-resourcesfuzzinglabs-practice+4
3144 years ago
xss-payload-list preview

xss-payload-list

GitHubh3x0v3rl0rd/xss-payload-list

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.

curated-resourceseducationvulnerability-analysis+2
5 years ago
moveit-transfer-cve-2023-34362 preview

moveit-transfer-cve-2023-34362

GitHubhorrister/moveit-transfer-cve-2023-34362

Curated vulnerability research repository with in-depth writeups, PoC scripts, and IOC detection tools for real-world security incidents like…

curated-resourceseducationexploitation+6
13 months ago
PAYLOAD-LISTS preview

PAYLOAD-LISTS

GitHubnu11secur1ty/payload-lists

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

curated-resourceseducationpayload-generation+3
41 month ago
shellshocker-pocs preview

shellshocker-pocs

GitHubmubix/shellshocker-pocs

Collection of Proof of Concepts and Potential Targets for #ShellShocker

curated-resourcesexploitationpenetration-testing+3
8896 years ago
cms-made-simple-python3 preview

cms-made-simple-python3

GitHubjagdeepsinghceh/cms-made-simple-python3

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

educationexploitationpassword-cracking+3
210 months ago
Vulnerability_PoC preview

Vulnerability_PoC

GitHubnumencyber/vulnerability_poc

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

binary-exploitationcurated-resourceseducation+3
3305 months ago
Previous12Next