Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
170 results
malicious-pdf preview

malicious-pdf

GitHubjonaslejon/malicious-pdf

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

data-exfiltrationeducationexploitation+6
4.3k
6 days ago
JS-Tap preview

JS-Tap

GitHubhoodoer/js-tap

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

command-and-controldata-exfiltrationinformation-gathering+8
4791 month ago
cromos preview

cromos

GitHubjimywork/cromos

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

command-and-controldata-exfiltrationlateral-movement+5
1248 years ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
WebView2-Cookie-Stealer preview

WebView2-Cookie-Stealer

GitHubmrd0x/webview2-cookie-stealer

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

data-exfiltrationinformation-gatheringpassword-attacks+2
2674 years ago
N1QLMap preview

N1QLMap

GitHubfsecurelabs/n1qlmap

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

database-securitydata-exfiltrationpenetration-testing+1
756 years ago
XBadManners preview

XBadManners

GitHubttffdd/xbadmanners

Tool for CVE-2018-16323

data-exfiltrationexploitationmemory-forensics+2
837 years ago
Log4jCenter preview

Log4jCenter

GitHubpuzzlepeaches/log4jcenter

Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

command-and-controldata-exfiltrationexploitation+3
1034 years ago
cve-2016-1764 preview

cve-2016-1764

GitHubmoloch--/cve-2016-1764

Extraction of iMessage Data via XSS

data-exfiltrationexploitationinformation-gathering+4
5110 years ago
CVE-2020-11579 preview

CVE-2020-11579

GitHubshieldersec/cve-2020-11579

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

database-securitydata-exfiltrationexploitation+3
252 years ago
kyocera-cve-2022-1026 preview

kyocera-cve-2022-1026

GitHubac3lives/kyocera-cve-2022-1026

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords

data-exfiltrationexploitationinformation-gathering+3
263 years ago
web-inf-path-trav preview

web-inf-path-trav

GitHubinvicti-security/web-inf-path-trav

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

data-exfiltrationexploitationpenetration-testing+3
333 years ago
CVE-2026-26980 preview

CVE-2026-26980

GitHubvognik/cve-2026-26980

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

database-securitydata-exfiltrationexploitation+4
1017 days ago
Apache-OFBiz-Directory-Traversal-exploit preview

Apache-OFBiz-Directory-Traversal-exploit

GitHubabsholi7ly/apache-ofbiz-directory-traversal-exploit

Exploit for Apache OFBiz CVE-2024-32113 path traversal via crafted XML-RPC requests, enabling arbitrary file read and potential command execution on…

data-exfiltrationexploitationpenetration-testing+3
162 years ago
CVE-2020-17518 preview

CVE-2020-17518

GitHubqmf0c3uk/cve-2020-17518

Python exploit for CVE-2020-17518, allowing arbitrary file write via Apache Flink REST API. Supports single target and batch scanning from a file.

data-exfiltrationexploitationremote-access-tool+2
75 years ago
CVE-2022-26159-Ametys-Autocompletion-XML preview

CVE-2022-26159-Ametys-Autocompletion-XML

GitHubp0dalirius/cve-2022-26159-ametys-autocompletion-xml

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

crawlerdata-exfiltrationexploitation+3
144 years ago
CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read preview

CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read

GitHubgeorge0papasotiriou/cve-2026-21015-php-filter-chain-arbitrary-file-read

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

data-exfiltrationexploitationinformation-gathering+4
29 days ago
CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD preview

CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD

GitHubluth1er/cve-2017-18345-com_joomanager-arbitrary-file-download

The Joomanager component through 2.0.0 for Joomla! has an Arbitrary File Download issue, resulting in exposing the Credentials of the DataBase.

data-exfiltrationexploitationinformation-gathering+3
77 years ago
Previous12…10Next