Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
Preproduce-CVE-2021-41773 preview

Preproduce-CVE-2021-41773

GitHubluongchivi/preproduce-cve-2021-41773

PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

educationexploitationpenetration-testing+3
1 year ago
CVE-2025-29927-Sigma-Rule preview

CVE-2025-29927-Sigma-Rule

GitHubelshaheedy/cve-2025-29927-sigma-rule

Sigma rule for detecting CVE-2025-29927 exploitation via suspicious x-middleware-subrequest HTTP headers in Next.js applications, with detection…

educationintrusion-detectionlog-analysis+3
1 year ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubpurgedemo/cve-2018-6574

Proof-of-concept exploit for CVE-2018-6574, a Go language vulnerability allowing remote code execution via crafted HTTP requests.

exploitationvulnerability-analysisweb-security
5 years ago
vuln-CVE-2022-41082 preview

vuln-CVE-2022-41082

GitHubnotareaperbutdr34p3r/vuln-cve-2022-41082

https & http

exploitationnetwork-securitypenetration-testing+3
3 years ago
CVE-2024-41713-Scan preview

CVE-2024-41713-Scan

GitHubamanverma-wsu/cve-2024-41713-scan

Python script to detect CVE-2024-41713 directory traversal in Apache HTTP Server, providing response snippets for verification. For educational and…

educationexploitationpenetration-testing+2
1 year ago
dromara__hutool_CVE-2018-17297_4-1-1111 preview

dromara__hutool_CVE-2018-17297_4-1-1111

GitHubshoucheng3/dromara__hutool_cve-2018-17297_4-1-1111

Comprehensive Java utility library providing modules for cryptography, HTTP client, caching, JSON, scripting, and captcha generation, simplifying…

captcha-bypasscryptographyencryption-decryption-tools+3
1 year ago
subdomain-tko preview

subdomain-tko

GitHubrandomrobbiebf/subdomain-tko

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

dns-analysisreconnaissancesubdomain-enumeration+2
6 years ago
tough-cookie-patch-cve-2023-26136 preview

tough-cookie-patch-cve-2023-26136

GitHubguy2610/tough-cookie-patch-cve-2023-26136

RFC6265-compliant cookie parsing and CookieJar management library for Node.js, with CVE-2023-26136 security patch. Supports cookie creation,…

authenticationencryption-decryption-toolsgeneral-purpose-utilities+2
1 year ago
BlackThrone preview

BlackThrone

GitHubprogramfilesx86/blackthrone

Network packets & HTTP sockets captor || Alternative of Burp Collaborator

information-gatheringreconnaissancevulnerability-analysis+1
4 years ago
dbdtct preview

dbdtct

GitHubyousseflahouifi/dbdtct

Python-based scanner that detects debug mode misconfigurations in web applications using multiple HTTP methods and fingerprinting techniques to…

misconfigurationpenetration-testingvulnerability-scanners+1
1 year ago
external_curl_AOSP10_r33_CVE-2021-22924 preview

external_curl_AOSP10_r33_CVE-2021-22924

GitHubtrinadh465/external_curl_aosp10_r33_cve-2021-22924

Command-line tool and library for transferring data using URL syntax, supporting various protocols including HTTP, FTP, and more.

general-purpose-utilitiesnetwork-securityscripting-automation+2
4 years ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
954 days ago
Roxy preview

Roxy

GitHubvid4l-07/roxy

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

api-security-testingpenetration-testingutilities-frameworks+3
47 days ago
cve-2026-22732-demo preview
Archived

cve-2026-22732-demo

GitHubsemgrep/cve-2026-22732-demo

Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped

educationexploitationpapers-research+2
5 months ago
CVE-2026-73315 preview

CVE-2026-73315

GitHubbombobombone/cve-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

exploitationvulnerability-analysisweb-application-exploitation+1
7 days ago
CVE-2026-63642 preview

CVE-2026-63642

GitHubhakaioffsec/cve-2026-63642

Proof-of-concept exploit scripts for CVE-2026-63642 and CVE-2026-63643, SSRF vulnerabilities in MagicMirror²'s Calendar module allowing…

exploitationpenetration-testingvulnerability-analysis+2
5 days ago
CVE-2026-42536-PoC preview

CVE-2026-42536-PoC

GitHuberberkan/cve-2026-42536-poc

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content

exploitationpapers-researchvulnerability-analysis+2
2 days ago
CVE-2025-60876 preview
Archived

CVE-2025-60876

GitHubsirredbeard/cve-2025-60876

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

exploitationfuzzingpenetration-testing+3
3 months ago
Previous1…171819…25Next