Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
ParrotNG preview

ParrotNG

GitHubikkisoft/parrotng

Java-based tool to detect Adobe Flex SWF files vulnerable to CVE-2011-2461, usable as a command-line utility or Burp Suite passive scanner plugin.

exploitationpenetration-testingstatic-analysis+3
48
11 years ago
cve-2025-55182-scanner preview

cve-2025-55182-scanner

GitHubxkillbit/cve-2025-55182-scanner

Passive vulnerability scanner for CVE-2025-55182 and CVE-2025-66478, detecting unauthenticated RCE in React Server Components via framework…

exploitationinformation-gatheringpenetration-testing+3
410 months ago
Burp_VulPscan preview

Burp_VulPscan

GitHubkkx600/burp_vulpscan

Passive Burp Suite plugin for scanning CVE-2022-22947 and integrating high-threat POCs into automated web vulnerability detection workflows.

educationexploitationpenetration-testing+3
24 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubmahaveer-choudhary/cve-2025-55182

A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool…

code-analysisexploitationpenetration-testing+3
9 months ago
SILENTCHAIN preview

SILENTCHAIN

GitHubsilentchainai/silentchain

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

ai-securityapi-security-testingcode-analysis+8
4622 days ago
freddy preview

freddy

GitHubnccgroup/freddy

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

code-analysisexploitationpenetration-testing+2
5805 years ago
PenScope preview

PenScope

GitHubspider12223/penscope

Passive recon & attack surface mapper — zero requests sent

crawlerexploitationinformation-gathering+7
375 months ago
text4shellburpscanner preview

text4shellburpscanner

GitHubf0ng/text4shellburpscanner

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

exploitationpenetration-testingvulnerability-scanners+2
203 years ago
CVE-2026-18351 preview

CVE-2026-18351

GitHubjohenlastgen-jlg/cve-2026-18351

Mass exploit tool for CVE-2026-18351, an unauthenticated arbitrary file upload to RCE in Elementor Forms <= 1.6.0, with passive probing, shell…

exploitationpayload-developmentpenetration-testing+5
125 days ago
CVE-2026-48908-by-yora preview

CVE-2026-48908-by-yora

GitHubyora1928/cve-2026-48908-by-yora

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

exploitationinformation-gatheringpayload-generation+7
21 month ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
CVE-2026-56291 preview

CVE-2026-56291

GitHub0xdenis77/cve-2026-56291

Mendeteksi versi (passive detection) & Exploitation CVE POC

exploitationinformation-gatheringpenetration-testing+3
12 months ago
CVE-2021-44228-Apache-Log4j-Rce preview

CVE-2021-44228-Apache-Log4j-Rce

GitHubkannthu/cve-2021-44228-apache-log4j-rce

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection payloads, WAF bypass techniques, and passive scanning integration for…

exploitationpayload-developmentpenetration-testing+3
4 years ago
active-scan-plus-plus preview

active-scan-plus-plus

GitHubportswigger/active-scan-plus-plus

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, code injection, and known CVEs like…

api-security-testingdefensive-toolspenetration-testing+6
2572 months ago