Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
70 results
jetty_9.4.31_CVE-2023-26048 preview

jetty_9.4.31_CVE-2023-26048

GitHubtrinadh465/jetty_9.4.31_cve-2023-26048
general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
2 years ago
jetty_9.4.31_CVE-2021-34428 preview

jetty_9.4.31_CVE-2021-34428

GitHubtrinadh465/jetty_9.4.31_cve-2021-34428
general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
2 years ago
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

api-security-testingcrawlerdevsecops+8
121 month ago
MasterHttpRelayVPN-RUST preview

MasterHttpRelayVPN-RUST

GitHubtherealaleph/masterhttprelayvpn-rust

Rust port of @masterking32's MasterHttpRelayVPN — all credit to @masterking32 for the original idea and Python implementation. Free DPI bypass via a…

dns-analysisweb-security
3.6k2 months ago
CVE-2026-42530 preview

CVE-2026-42530

GitHubv4ltonn/cve-2026-42530

Scanner PoC for CVE-2026-42530 -- nginx 1.31.0-1.31.1 HTTP/3 QPACK encoder stream Use-After-Free (CVSS 9.2)

exploitationfuzzingnetwork-security+2
42 months ago
CVE-2021-30809-OOM preview

CVE-2021-30809-OOM

GitHubseregonwar/cve-2021-30809-oom

CVE-2021-30809 UAF use-after-free PoC

binary-exploitationeducationexploitation+2
41 year ago
Galaxy-Bugbounty-Checklist preview

Galaxy-Bugbounty-Checklist

GitHub0xmaximus/galaxy-bugbounty-checklist

Tips and Tutorials for Bug Bounty and also Penetration Tests.

curated-resourceseducationosint+3
2.1k10 months ago
Apache-Solr-Arbitrary-File-Read preview

Apache-Solr-Arbitrary-File-Read

GitHubmurataydemir/apache-solr-arbitrary-file-read

[No CVE] Apache Solr Arbitrary File Read

data-exfiltrationexploitationinformation-gathering+4
15 years ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12713 years ago
xpfarm preview

xpfarm

GitHuba3-n/xpfarm

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

ai-securitybinary-analysiseducation+6
444 months ago
CVE-2021-31166 preview

CVE-2021-31166

GitHubzha0gongz1/cve-2021-31166

PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause…

binary-exploitationexploitationpenetration-testing+2
95 years ago
CVE-2026-2764-but-with-wasm preview

CVE-2026-2764-but-with-wasm

GitHubsneakynachos/cve-2026-2764-but-with-wasm

Proof-of-concept exploit chain for Firefox JIT CVE-2026-2764, chaining JIT miscompilation and use-after-free into arbitrary read/write and WASM…

binary-exploitationexploitationpayload-development+3
110 days ago
CVE-2023-38434 preview

CVE-2023-38434

GitHubhalcy0nic/cve-2023-38434

Proof of Concept for CVE-2023-38434

binary-analysisexploitationfuzzing+2
13 years ago
CVE-2021-31166 preview
Archived

CVE-2021-31166

GitHub0vercl0k/cve-2021-31166

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

binary-exploitationexploitationremote-access-tool+2
8275 years ago
testssl.sh preview

testssl.sh

GitHubtestssl/testssl.sh

Testing TLS/SSL encryption anywhere on any port

cryptographynetwork-securitypenetration-testing+2
9.2k5 days ago
policymaker preview

policymaker

GitHubdisclose/policymaker

A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.

curated-resourcesdns-analysiseducation+2
169 days ago
cybersecurity-interview-questions preview

cybersecurity-interview-questions

GitHubexcalibra/cybersecurity-interview-questions

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…

curated-resourceseducationincident-response+4
1326 days ago
ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-23457_2-2-3-1
api-securityauthentication-authorizationcode-analysis+6
1 year ago
Previous1234Next