Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
487 results
w13scan preview

w13scan

GitHubw-digital-scanner/w13scan

Passive and active web vulnerability scanner with plugin-based detection for XSS, SQL injection, command injection, and sensitive file disclosure.…

penetration-testingvulnerability-scannersweb-security+1
1.9k
4 years ago
subjs preview

subjs

GitHublc/subjs

Fetches javascript file from a list of URLS or subdomains.

information-gatheringosintreconnaissance+1
8621 year ago
pentest-machine preview

pentest-machine

GitHubdanmcinerney/pentest-machine

Automates some pentest jobs via nmap xml file

information-gatheringnetwork-securitypassword-attacks+3
3267 years ago
lulzbuster preview

lulzbuster

GitHubnoptrix/lulzbuster

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

fuzzinginformation-gatheringpenetration-testing+3
1411 month ago
Lfi-Space preview

Lfi-Space

GitHubcapture0x/lfi-space

Automated Local File Inclusion (LFI) vulnerability scanner with Google Dork search and targeted URL scan modes for web application security testing.

information-gatheringpenetration-testingvulnerability-scanners+1
1123 months ago
Network-Analysis-Tools preview

Network-Analysis-Tools

GitHubazizaltuntas/network-analysis-tools

Pcap (capture file) Analysis Toolkit(v.1)

forensicsinformation-gatheringnetwork-forensics+2
1109 years ago
exploit-grafana-CVE-2021-43798 preview

exploit-grafana-CVE-2021-43798

GitHubpedrohavay/exploit-grafana-cve-2021-43798

This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).

educationexploitationinformation-gathering+3
464 years ago
CVE-2026-48908-PoC preview

CVE-2026-48908-PoC

GitHubpapageo75/cve-2026-48908-poc

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning,…

code-analysiseducationexploitation+5
152 months ago
tinyfilemanager-wh1z-edition preview

tinyfilemanager-wh1z-edition

GitHubpinoywh1z/tinyfilemanager-wh1z-edition

Effortlessly browse and manage your files with ease using Tiny File Manager [WH1Z-Edition], a compact single-file PHP file manager.

privacyred-teamingweb-security
252 years ago
CVE-2024-4367_test preview

CVE-2024-4367_test

GitHubj1nksc/cve-2024-4367_test

Proof-of-concept exploit for CVE-2024-4367, demonstrating a PDF-based vulnerability with a hosted POC file for testing and educational purposes.

educationexploitationpenetration-testing+2
17 days ago
CVE-2020-28948-and-CVE-2020-28949 preview

CVE-2020-28948-and-CVE-2020-28949

GitHub0x240x23elu/cve-2020-28948-and-cve-2020-28949

Proof-of-concept demonstration for CVE-2020-28948 and CVE-2020-28949, PHP Archive_Tar path traversal and arbitrary file write vulnerabilities.

code-analysiseducationexploitation+2
65 years ago
CVE-2026-63223-POC preview

CVE-2026-63223-POC

GitHubimbas007/cve-2026-63223-poc

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

educationexploitationlabs-practice+5
227 days ago
CVE-2021-41773-Apache-Lab preview

CVE-2021-41773-Apache-Lab

GitHubs-amnajafri/cve-2021-41773-apache-lab

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

educationexploitationlabs-practice+4
16 days ago
wp2shell-Hestia-Scanner preview

wp2shell-Hestia-Scanner

GitHubbytespulse-oe/wp2shell-hestia-scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

ai-securitydefensive-toolsforensics+7
226 days ago
Metabase_CVE-2021-41277 preview

Metabase_CVE-2021-41277

GitHubvulnmachines/metabase_cve-2021-41277

Exploit for Metabase CVE-2021-41277, a local file inclusion vulnerability in custom GeoJSON map support, allowing unauthorized file access.

ctfcurated-resourceseducation+3
44 years ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubrecorded-texteditor120/cve-2026-31802

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

curated-resourceseducationexploitation+3
18 days ago
Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation preview

Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation

GitHubzedocun/incident-analysis-response-check-point-security-gateway-cve-2024-24919-lfi-exploitation

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

digital-forensicseducationincident-response+7
129 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubdr-d25/cve-2026-49049

Technical analysis and Proof of Concept (PoC) for CVE-2026-49049, an unauthenticated arbitrary file write vulnerability in JoomShaper Helix3 for…

educationexploitationpenetration-testing+3
1 month ago
Previous1…232425…28Next