Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
social-engineer-toolkit preview

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

exploitationexploit-frameworksimpersonation-tools+9
15.3k
3 months ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

anti-botids-ips-evasionmisconfiguration+4
3.3k10h 1m ago
CVE-2023-33381-MitraStar-GPT-2741GNAC preview

CVE-2023-33381-MitraStar-GPT-2741GNAC

GitHubduality084/cve-2023-33381-mitrastar-gpt-2741gnac

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

binary-analysisembedded-systems-securityexploitation+4
133 years ago
pixload preview

pixload

GitHubsighook/pixload

Image Payload Creating/Injecting tools

payload-developmentpayload-generationsteganography+1
1.3k3 years ago
svg-cheatsheet preview

svg-cheatsheet

GitHuballanlw/svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

curated-resourceseducationinformation-gathering+4
8056 years ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
24414h 37m ago
CVE-2025-22131-PoC preview

CVE-2025-22131-PoC

GitHubzzn1nj4/cve-2025-22131-poc

PoC for CVE-2025-22131

exploitationpayload-generationphishing-tools+2
11 year ago
PoC-CVE-2024-33883 preview

PoC-CVE-2024-33883

GitHubgrantzile/poc-cve-2024-33883

PoC of CVE-2024-33883, RCE vulnerability of ejs.

code-analysiseducationexploitation+3
52 years ago
Text4ShellPayloads preview

Text4ShellPayloads

GitHubstavrosgns/text4shellpayloads

This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability

exploitationpayload-generationpenetration-testing+2
33 years ago
cve-2017-7269-tool preview

cve-2017-7269-tool

GitHubzcgonvh/cve-2017-7269-tool

CVE-2017-7269 to webshell or shellcode loader

exploitationpayload-developmentpenetration-testing+2
889 years ago
CVE-2025-7384 preview

CVE-2025-7384

GitHubdungsocool/cve-2025-7384

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

educationexploitationlabs-practice+2
1 month ago
CVE-2022-37201 preview

CVE-2022-37201

GitHubagainstthelight/cve-2022-37201

CVE-2022-37201 POC

exploitationpenetration-testingvulnerability-analysis+1
3 years ago
CVE-2026-4692-trust-me-im-in-rdm preview

CVE-2026-4692-trust-me-im-in-rdm

GitHubsneakynachos/cve-2026-4692-trust-me-im-in-rdm

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

exploitationexploit-frameworkspayload-development+4
117 days ago
CVE-2024-49368 preview

CVE-2024-49368

GitHubaashay221999/cve-2024-49368

Explorations of CVE-2024-49368 + Exploit Development

command-and-controleducationexploitation+3
1 year ago
cve-2022-1388-1veresk preview

cve-2022-1388-1veresk

GitHubiveresk/cve-2022-1388-1veresk

Simple shell script for the exploit

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2020-6287-exploit preview

CVE-2020-6287-exploit

GitHubduc-nt/cve-2020-6287-exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original…

educationexploitationvulnerability-analysis+1
966 years ago
CVE-2025-33053_PoC preview

CVE-2025-33053_PoC

GitHub4n4s4zi/cve-2025-33053_poc

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

command-and-controlexploitationlateral-movement+3
11 year ago
CVE-2021-4773 preview

CVE-2021-4773

GitHubalexs18/cve-2021-4773

Step-by-step tutorial demonstrating how to set up a vulnerable Apache 2.4.49 environment and exploit CVE-2021-41773 path traversal using Kali Linux…

educationexploitationlabs-practice+3
10 months ago
Previous12Next