Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
deep-C preview

deep-C

GitHubkishorbal/deep-c

Android deeplink misconfiguration detector and exploitation tool

ai-securityandroid-securitydynamic-analysis-sandboxing+8
91
6 months ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.8k3 months ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k3 months ago
LLMMap preview

LLMMap

GitHubhellsender01/llmmap

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

ai-securityapi-security-testingdynamic-analysis-sandboxing+6
2076 months ago
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

dynamic-code-analysiseducationencryption-decryption-tools+7
472 months ago
reactguard preview

reactguard

GitHubtheori-io/reactguard

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

code-analysispenetration-testingstatic-analysis+3
188 months ago
CTT-Enhanced-CVE-2026-46339-Exploit-Engine preview

CTT-Enhanced-CVE-2026-46339-Exploit-Engine

GitHubsimoesctt/ctt-enhanced-cve-2026-46339-exploit-engine

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

exploitationpayload-developmentred-teaming+3
19 days ago
spring-shell-vuln preview

spring-shell-vuln

GitHubsnip3r69/spring-shell-vuln

Spring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this…

educationexploitationpenetration-testing+2
14 years ago
apache__myfaces_CVE-2011-4367_2-0-11 preview

apache__myfaces_CVE-2011-4367_2-0-11

GitHubshoucheng3/apache__myfaces_cve-2011-4367_2-0-11

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

code-analysisstatic-analysisvulnerability-analysis+2
1 year ago
CVE-2022-27925 preview

CVE-2022-27925

GitHubsh4den/cve-2022-27925

A loader for zimbra 2022 rce (cve-2022-27925)

educationexploitationreconnaissance+2
182 months ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubsh4den/cve-2022-36804

A loader for bitbucket 2022 rce (cve-2022-36804)

exploitationpenetration-testingremote-access-tool+2
122 months ago
CVE-2026-75429_PowerJob_friend_process_RCE preview

CVE-2026-75429_PowerJob_friend_process_RCE

GitHubunpredictable21/cve-2026-75429_powerjob_friend_process_rce

Unauthenticated remote code execution exploit for PowerJob Server via Groovy injection in the /friend/process endpoint, enabling arbitrary command…

exploitationpenetration-testingremote-access-trojan+2
1 month ago
CVE-2016-6366 preview

CVE-2016-6366

GitHubrisksense-ops/cve-2016-6366

Public repository for improvements to the EXTRABACON exploit

binary-analysisexploitationexploit-frameworks+8
1639 years ago
cisco_asa_research preview

cisco_asa_research

GitHubjbaines-r7/cisco_asa_research

Cisco ASA Software and ASDM Security Research

exploitationexploit-frameworksinformation-gathering+7
884 years ago
CVE-2022-47986 preview

CVE-2022-47986

GitHubmauricelambert/cve-2022-47986

CVE-2022-47986: Python, Ruby, NMAP and Metasploit modules to exploit the vulnerability.

exploitationexploit-frameworksweb-application-exploitation
13 years ago
macro_pack preview
Archived

macro_pack

GitHubsevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exploit-frameworkslateral-movementpayload-generation+6
2.3k2 years ago