Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
65 results
social-engineer-toolkit preview

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

exploit-frameworksinformation-gatheringpayload-generation+5
15.2k
2 months ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

ids-ips-evasionmisconfigurationvulnerability-scanners+3
3.2k2 days ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.7k3 days ago
CVE-2020-6287-exploit preview

CVE-2020-6287-exploit

GitHubduc-nt/cve-2020-6287-exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original…

educationexploitationvulnerability-analysis+1
966 years ago
CVE-2026-51947-Advisory preview

CVE-2026-51947-Advisory

GitHubtimtimxs/cve-2026-51947-advisory

Pivotal CRM's patch for an initial deserialization vulnerability was incomplete. The fix switched from BinaryFormatter to JSON.NET but left…

code-analysisexploitationpenetration-testing+2
1 month ago
CVE-2025-57833 preview

CVE-2025-57833

GitHubmkway/cve-2025-57833

We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.

code-analysiseducationpenetration-testing+3
211 months ago
CVE-2025-2563 preview

CVE-2025-2563

GitHubnxploited/cve-2025-2563

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

educationexploitationpayload-development+5
4 months ago
Explosive-As-Hell-MCS-Qualifer-Web-500 preview

Explosive-As-Hell-MCS-Qualifer-Web-500

GitHubabdullahmaqbool22/explosive-as-hell-mcs-qualifer-web-500

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

binary-exploitationctfeducation+7
4 months ago
CVE-2021-3129---Laravel-RCE preview

CVE-2021-3129---Laravel-RCE

GitHublukwagoasuman/cve-2021-3129---laravel-rce

## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands…

exploitationvulnerability-analysisweb-application-exploitation
11 year ago
CVE-2023-30212-POC-DOCKER-FILE preview

CVE-2023-30212-POC-DOCKER-FILE

GitHubrishipatidar/cve-2023-30212-poc-docker-file

This repository provides a Docker container for simulating the CVE-2023-30212 vulnerability, allowing you to practice and understand its impact. It…

educationexploitationlabs-practice+3
13 years ago
setup-cve-2015-8562 preview

setup-cve-2015-8562

GitHublorenzodegiorgi/setup-cve-2015-8562

Docker-compose to set up a test environment for exploiting CVE-2015-8562

educationexploitationlabs-practice+3
5 years ago
pixload preview

pixload

GitHubsighook/pixload

Image Payload Creating/Injecting tools

payload-developmentpayload-generationsteganography+1
1.3k3 years ago
PwnAdventure3 preview

PwnAdventure3

GitHubliveoverflow/pwnadventure3

PwnAdventure3 Server

binary-exploitationctfeducation+5
6837 years ago
svg-cheatsheet preview

svg-cheatsheet

GitHuballanlw/svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

curated-resourceseducationinformation-gathering+4
8026 years ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
2421 month ago
ysoserial-cve-2018-2628 preview

ysoserial-cve-2018-2628

GitHubtdy218/ysoserial-cve-2018-2628

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

exploitationpayload-developmentpenetration-testing+2
1148 years ago
cve-2017-7269-tool preview

cve-2017-7269-tool

GitHubzcgonvh/cve-2017-7269-tool

CVE-2017-7269 to webshell or shellcode loader

exploitationpayload-developmentpenetration-testing+2
889 years ago
django_cve_2019_19844_poc preview

django_cve_2019_19844_poc

GitHubryu22e/django_cve_2019_19844_poc

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

authenticationexploitationpenetration-testing+2
1006 years ago
Previous1234Next