Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
486 results
CVE-2024-23897 preview

CVE-2024-23897

GitHubdungsocool/cve-2024-23897

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

educationexploitationlabs-practice+2
1 month ago
Burp_Collector preview

Burp_Collector

GitHubsajibuu/burp_collector

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

api-security-testinginformation-gatheringpenetration-testing+4
102 years ago
CVE-2026-37748 preview

CVE-2026-37748

GitHubmenevarad007/cve-2026-37748

Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

exploitationpayload-developmentpenetration-testing+3
4 months ago
CVE-2018-16373 preview

CVE-2018-16373

GitHubsnappyjack/cve-2018-16373

Frog CMS 0.9.5 has an Upload > vulnerability that can create files via > /admin/?/plugin/file_manager/save

exploitationmisconfigurationpenetration-testing+2
7 years ago
react2shell preview

react2shell

GitHubcahyod/react2shell

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

code-analysisstatic-analysissupply-chain-security+2
18 months ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4793 years ago
pwndrop preview

pwndrop

GitHubkgretzky/pwndrop

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

phishing-toolsred-teamingweb-security
2.3k5 years ago
Upload_Bypass preview

Upload_Bypass

GitHubsajibuu/upload_bypass

A simple tool for bypassing file upload restrictions.

exploitationpayload-generationpenetration-testing+2
9082 years ago
CVE-2026-14431 preview

CVE-2026-14431

GitHubjaf0rk/cve-2026-14431

Exploit for CVE-2026-14431 providing V8 sandbox read/write primitives via a crafted JavaScript file, targeting Chromium's V8 engine on Linux x64.

binary-exploitationexploitationmemory-forensics+2
1 month ago
beef preview

beef

GitHubbeefproject/beef

The Browser Exploitation Framework Project

command-and-controlexploitationexploit-frameworks+8
11.0k1 day ago
Grawler preview

Grawler

GitHuba3h1nt/grawler

Grawler is a tool written in PHP which comes with a web interface that automates the task of using google dorks, scrapes the results, and stores them…

crawlerinformation-gatheringosint+1
2122 years ago
hakrawler preview

hakrawler

GitHubhakluke/hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

crawlerinformation-gatheringpenetration-testing+2
5.1k25 days ago
dirsearch preview

dirsearch

GitHubevilsocket/dirsearch

Concurrent web directory and file brute-forcing tool that performs HEAD requests against a target URL using a wordlist, with support for custom…

information-gatheringpenetration-testingvulnerability-scanners+1
2794 years ago
CVE-2025-61686-PoC preview

CVE-2025-61686-PoC

GitHubboroeurnprach/cve-2025-61686-poc

React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the…

exploitationmisconfigurationvulnerability-analysis+1
7 months ago
certbot preview

certbot

GitHubcertbot/certbot

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

authentication-authorizationcloud-securityconfiguration-auditing+3
33.2k4 days ago
cariddi preview

cariddi

GitHubedoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

crawlerinformation-gatheringosint+4
3.8k1 month ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubthemehackers/cve-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

exploitationinformation-gatheringpayload-generation+3
101 year ago
IntruderPayloads preview

IntruderPayloads

GitHub1n3/intruderpayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

curated-resourceseducationfuzzing+3
4.0k4 years ago
Previous12…27Next