Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
sharepoint-toolshell-micro-postmortem preview

sharepoint-toolshell-micro-postmortem

GitHubcameloo1/sharepoint-toolshell-micro-postmortem

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

curated-resourceseducationforensics+7
1
9 months ago
ToolShellFinder preview

ToolShellFinder

GitHubzach115th/toolshellfinder

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

digital-forensicsforensicsincident-response+5
10 months ago
secure-by-default-rce-demo preview

secure-by-default-rce-demo

GitHubmeganekos/secure-by-default-rce-demo

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

cloud-securitycontainer-securitydevsecops+6
9 months ago
CVE-2022-4047 preview

CVE-2022-4047

GitHubentroychang/cve-2022-4047

Unauthenticated arbitrary file upload exploit for WooCommerce Return Refund and Exchange plugin (CVE-2022-4047). Scans targets, uploads webshell, and…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2025-1974 preview

CVE-2025-1974

GitHub0xbingo/cve-2025-1974

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

cloud-securitycontainer-securityeducation+4
1 year ago
CVE-2024-24919-CHECKPOINT preview

CVE-2024-24919-CHECKPOINT

GitHubj4f9s5d2q7/cve-2024-24919-checkpoint

Exploit scanner for CVE-2024-24919 targeting Check Point Security Gateways. Scans IP lists, extracts /etc/passwd, /etc/shadow, and system logs from…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
log4shellwithlog4j2_13_3 preview

log4shellwithlog4j2_13_3

GitHubpaulvkitor/log4shellwithlog4j2_13_3

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

educationexploitationlabs-practice+2
4 years ago
CVE-2023-6895 preview

CVE-2023-6895

GitHubnles-crt/cve-2023-6895

Python script to scan websites for CVE-2023-6895 vulnerability. Sends crafted requests, checks responses, and logs exploitable URLs with progress bar…

educationexploitationinformation-gathering+3
2 years ago
cve-2021-27065 preview
Archived

cve-2021-27065

GitHubadamrpostjr/cve-2021-27065

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

digital-forensicsforensicsincident-response+3
115 years ago
waf-fu preview

waf-fu

GitHubconfused-binary/waf-fu

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

cloud-securitydefensive-toolsincident-response+6
21 month ago
dnsFookup preview

dnsFookup

GitHubmakuga01/dnsfookup

DNS rebinding toolkit

dns-analysisexploitationpenetration-testing+1
2563 years ago
AnonGT preview

AnonGT

GitHubgt0day/anongt

Redirect All Traffic Through Tor Network For Kali Linux

anti-botdns-analysisencryption-decryption-tools+7
2371 year ago
sharemylogin preview

sharemylogin

GitHubelandio-com/sharemylogin

Zero-Knowledge Credential Sharing

authenticationencryption-decryption-toolsprivacy+3
572 months ago
cve-2020-0618 preview

cve-2020-0618

GitHubwortell/cve-2020-0618

CVE-2020-0618 Honeypot

incident-responseintrusion-detectionthreat-intelligence+2
306 years ago
CVE-2021-38699-Stored-XSS preview

CVE-2021-38699-Stored-XSS

GitHubhuskyhacks/cve-2021-38699-stored-xss

Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS

exploitationpenetration-testingvulnerability-analysis+2
35 years ago
CVE-2025-56643 preview

CVE-2025-56643

GitHub0xbs0d27/cve-2025-56643

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

api-securityauthenticationexploitation+2
111 months ago
CVE-2025-10377 preview

CVE-2025-10377

GitHubnagisayumaa/cve-2025-10377

CVE-2025-10377

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
citrix-honeypot preview

citrix-honeypot

GitHubeliushhimel/citrix-honeypot

Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts

defensive-toolsnetwork-securitythreat-intelligence+2
6 years ago
Previous123Next