Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13165 results
TPASLog4ShellPoC preview
Archived

TPASLog4ShellPoC

GitHubcarlos-mesquita/tpaslog4shellpoc

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

payload-generationvulnerability-analysisexploitation+3
1
1 year ago
CVE-2018-1270 preview
Archived

CVE-2018-1270

GitHubcaledoniaproject/cve-2018-1270

Spring messaging STOMP protocol RCE

vulnerability-analysiscode-analysisexploitation+2
1138 years ago
CVE-2022-22965-GUItools preview
Archived

CVE-2022-22965-GUItools

GitHubbouquets-ai/cve-2022-22965-guitools

spring-core单个图形化利用工具,CVE-2022-22965及修复方案已出

vulnerability-analysisexploitationweb-application-exploitation+2
174 years ago
SC3010-Computer-Security preview
Archived

SC3010-Computer-Security

GitHubaipeacs/sc3010-computer-security

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

static-analysisvulnerability-analysiscode-analysis+6
3 months ago
CVE-2021-41773 preview
Archived

CVE-2021-41773

GitHub12345qwert123456/cve-2021-41773

Vulnerable configuration Apache HTTP Server version 2.4.49

container-securityvulnerability-analysisexploitation+3
3 years ago
CVE-2020-3452 preview
Archived

CVE-2020-3452

GitHub0x5ecf4ult/cve-2020-3452

CVE-2020-3452 exploit

vulnerability-analysisexploitationweb-application-exploitation+2
246 years ago
CVE-2019-9810 preview
Archived

CVE-2019-9810

GitHub0vercl0k/cve-2019-9810

Exploit for CVE-2019-9810 Firefox on Windows 64-bit.

exploitationshellcodeweb-application-exploitation+3
2276 years ago
CVE-2019-11708 preview
Archived

CVE-2019-11708

GitHub0vercl0k/cve-2019-11708

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

exploitationweb-application-exploitationpayload-development
6246 years ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

privilege-escalationvulnerability-scannersnetwork-mapping+8
5344 years ago
BypassFuzzer preview
Archived

BypassFuzzer

GitHubintrudir/bypassfuzzer

Fuzz 401/403/404 pages for bypasses

vulnerability-scannersids-ips-evasionweb-application-exploitation+3
4307 months ago
poc-graphql preview
Archived

poc-graphql

GitHubrighettod/poc-graphql

Research on GraphQL from an AppSec point of view.

vulnerability-analysisweb-application-exploitationapi-security-testing+3
4183 years ago
heyserial preview
Archived

heyserial

GitHubmandiant/heyserial

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

payload-generationvulnerability-analysisexploitation+6
1423 years ago
request_smuggler preview
Archived

request_smuggler

GitHubsh1yo/request_smuggler

Http request smuggling vulnerability scanner

vulnerability-scannersweb-vulnerability-scannersweb-application-exploitation+3
2284 years ago
AutoSQLi preview
Archived

AutoSQLi

GitHubclouedoc/autosqli

An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.

osintvulnerability-scannersdns-subdomain-enumeration+3
2715 years ago
lazyCSRF preview
Archived

lazyCSRF

GitHubtkmru/lazycsrf

A more useful CSRF PoC generator on Burp Suite

payload-generationvulnerability-analysisweb-application-exploitation+2
924 years ago
nginxpwner preview
Archived

nginxpwner

GitHubstark0de/nginxpwner

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

vulnerability-scannersweb-application-exploitationinformation-gathering+3
1.6k2 years ago
sqlmate preview
Archived

sqlmate

GitHubs0md3v/sqlmate

A friend of SQLmap which will do what you always expected from SQLmap.

password-crackingreconnaissancevulnerability-scanners+5
4537 years ago
Http-Asynchronous-Reverse-Shell preview
Archived

Http-Asynchronous-Reverse-Shell

GitHubonsec-fr/http-asynchronous-reverse-shell

[POC] Asynchronous reverse shell using the HTTP protocol.

ids-ips-evasionlateral-movementweb-application-exploitation+7
2721 year ago
Previous1…729730731732Next