Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
65 results
social-engineer-toolkit preview

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

exploit-frameworksinformation-gatheringpayload-generation+5
15.2k
2 months ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.7k3 days ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

ids-ips-evasionmisconfigurationvulnerability-scanners+3
3.2k2 days ago
pixload preview

pixload

GitHubsighook/pixload

Image Payload Creating/Injecting tools

payload-developmentpayload-generationsteganography+1
1.3k3 years ago
svg-cheatsheet preview

svg-cheatsheet

GitHuballanlw/svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

curated-resourceseducationinformation-gathering+4
8026 years ago
PwnAdventure3 preview

PwnAdventure3

GitHubliveoverflow/pwnadventure3

PwnAdventure3 Server

binary-exploitationctfeducation+5
6837 years ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
2421 month ago
ysoserial-cve-2018-2628 preview

ysoserial-cve-2018-2628

GitHubtdy218/ysoserial-cve-2018-2628

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

exploitationpayload-developmentpenetration-testing+2
1148 years ago
django_cve_2019_19844_poc preview

django_cve_2019_19844_poc

GitHubryu22e/django_cve_2019_19844_poc

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

authenticationexploitationpenetration-testing+2
1006 years ago
CVE-2020-6287-exploit preview

CVE-2020-6287-exploit

GitHubduc-nt/cve-2020-6287-exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original…

educationexploitationvulnerability-analysis+1
966 years ago
cve-2017-7269-tool preview

cve-2017-7269-tool

GitHubzcgonvh/cve-2017-7269-tool

CVE-2017-7269 to webshell or shellcode loader

exploitationpayload-developmentpenetration-testing+2
889 years ago
CVE-2021-30551 preview

CVE-2021-30551

GitHubxmzyshypnc/cve-2021-30551

my exp for chrome V8 CVE-2021-30551

binary-exploitationeducationexploitation+2
243 years ago
CVE-2017-6079-Blind-Command-Injection-In-Edgewater-Edgemarc-Devices-Exploit preview

CVE-2017-6079-Blind-Command-Injection-In-Edgewater-Edgemarc-Devices-Exploit

GitHubmostafasoliman/cve-2017-6079-blind-command-injection-in-edgewater-edgemarc-devices-exploit
exploitationremote-access-toolvulnerability-analysis+1
177 years ago
CVE-2023-33381-MitraStar-GPT-2741GNAC preview

CVE-2023-33381-MitraStar-GPT-2741GNAC

GitHubduality084/cve-2023-33381-mitrastar-gpt-2741gnac

CVE-2023-33381: OS command injection on MitraStar GPT-2741GNAC

binary-analysisembedded-systems-securityexploitation+4
133 years ago
poc-cve-2023-2868 preview

poc-cve-2023-2868

GitHubcfielding-r7/poc-cve-2023-2868
command-and-controlexploitationpenetration-testing+2
113 years ago
django_cve201919844 preview

django_cve201919844

GitHubandripwn/django_cve201919844

PoC for CVE-2019-19844 ( https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ )

educationexploitationpenetration-testing+2
85 years ago
CVE-2023-28343 preview

CVE-2023-28343

GitHubgobysec/cve-2023-28343

Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)

command-and-controlexploitationpenetration-testing+3
63 years ago
CVE-2019-11581 preview

CVE-2019-11581

GitHubpetrusviet/cve-2019-11581

Atlassian Jira unauthen template injection

educationexploitationpayload-development+3
64 years ago
Previous1234Next