Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
haptyc preview

haptyc

GitHubdefparam/haptyc

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

fuzzingpayload-generationpenetration-testing+1
93
5 years ago
CVE-2024-5274 preview

CVE-2024-5274

GitHubmistymntncop/cve-2024-5274

Exploit for CVE-2024-5274, a Chrome V8 DCHECK bytecode mismatch vulnerability that provides out-of-bounds read/write primitives for browser…

binary-exploitationexploitationvulnerability-analysis+1
862 years ago
CVE-2026-1010-WebSocket-Connection-Smuggling-via-Malformed-Upgrade-Header preview

CVE-2026-1010-WebSocket-Connection-Smuggling-via-Malformed-Upgrade-Header

GitHubgeorge0papasotiriou/cve-2026-1010-websocket-connection-smuggling-via-malformed-upgrade-header

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

exploitationpenetration-testingvulnerability-analysis+2
2 months ago
HTC preview

HTC

GitHubawesome-consumer-iot/htc

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

exploitationpassword-attacksreconnaissance+2
16 years ago
Exploit-CSRF-on-SCOPIA-XT-Desktop-version-8.3.915.4 preview

Exploit-CSRF-on-SCOPIA-XT-Desktop-version-8.3.915.4

GitHubv1n1v131r4/exploit-csrf-on-scopia-xt-desktop-version-8.3.915.4

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

exploitationpenetration-testingvulnerability-analysis+2
16 years ago
CVE-2025-55182-NSE preview

CVE-2025-55182-NSE

GitHubyunaranyancat/cve-2025-55182-nse

Meow

exploitationinformation-gatheringnetwork-security+3
10 months ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubjoojiii/cve-2025-29927

Proof-of-concept exploit for CVE-2025-29927 in Next.js 15.2.0, demonstrating a specific web application vulnerability for testing and educational…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
pocsploit preview

pocsploit

GitHubcckuailong/pocsploit

a lightweight, flexible and novel open source poc verification framework

exploit-frameworkspenetration-testingvulnerability-analysis+2
2374 years ago
lightweight_static_analysis preview

lightweight_static_analysis

GitHubnccgroup/lightweight_static_analysis

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

code-analysiseducationpenetration-testing+4
136 years ago
Owa-Valid-Login-Checker preview

Owa-Valid-Login-Checker

GitHubjenderal92/owa-valid-login-checker

Owa Valid Login Checker

authentication-authorizationinformation-gatheringpassword-attacks+2
4 months ago
npm-demo preview

npm-demo

GitHubalonnavon/npm-demo

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

code-analysiseducationvulnerability-analysis+2
7 months ago
heartbleed-bug preview

heartbleed-bug

GitHubtomdevman/heartbleed-bug

Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔

educationexploitationpenetration-testing+2
7 years ago
Internet-Security-Project---CVE-2021-26814 preview

Internet-Security-Project---CVE-2021-26814

GitHubpaolorabbito/internet-security-project---cve-2021-26814

Educational exploit demonstration for CVE-2021-26814 targeting Wazuh v4.0.3, with step-by-step exploitation and remediation code for university-level…

code-analysiseducationexploitation+3
4 years ago
trellis-cve-2018-6389 preview
Archived

trellis-cve-2018-6389

GitHubitinerisltd/trellis-cve-2018-6389

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

configuration-auditingdefensive-toolsdevsecops+3
138 years ago
Log4j_Vulnerability_Demo preview

Log4j_Vulnerability_Demo

GitHubchandanshastri/log4j_vulnerability_demo

A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )

educationexploitationlog-analysis+2
34 years ago
CVE-2022-4096 preview

CVE-2022-4096

GitHubaminetitrofine/cve-2022-4096

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

dns-analysiseducationexploitation+3
3 years ago
thief_raccoon preview

thief_raccoon

GitHubdavenisc/thief_raccoon

Educational phishing simulation tool that mimics OS login screens to capture credentials for cybersecurity awareness training. Supports Windows,…

educationphishingphishing-tools+2
1832 years ago
Previous1234Next