Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
488 results
CVE-2024-24919 preview

CVE-2024-24919

GitHubbytenull00/cve-2024-24919

Scans multiple URLs for the CVE-2024-24919 vulnerability in Check Point products, providing a quick and simple batch-checking script.

exploitationpenetration-testingreconnaissance+2
3
2 years ago
CVE-2025-56223 preview

CVE-2025-56223

GitHubsaykino/cve-2025-56223

Documentation of CVE-2025-56223, a denial-of-service vulnerability in Ascertia SigningHub's Upload Document API, allowing unrestricted file uploads…

api-securitypenetration-testingvulnerability-analysis+1
10 months ago
Instagram-Notes-Audio-Leakage-via-URL-Extraction-Fixed preview

Instagram-Notes-Audio-Leakage-via-URL-Extraction-Fixed

GitHubi12gocaj/instagram-notes-audio-leakage-via-url-extraction-fixed

Informe técnico de una vulnerabilidad ya corregida en Instagram Notes que exponía el audio original de vídeos mediante URLs directas.

educationinformation-gatheringpapers-research+2
81 year ago
CVE-2025-24813-Scanner preview

CVE-2025-24813-Scanner

GitHubmattb709/cve-2025-24813-scanner

CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file…

exploitationinformation-gatheringpenetration-testing+3
51 year ago
Upload_Bypass preview

Upload_Bypass

GitHubsajibuu/upload_bypass

A simple tool for bypassing file upload restrictions.

exploitationpayload-generationpenetration-testing+2
9082 years ago
CVE-2021-46079 preview

CVE-2021-46079

GitHubsanupl/cve-2021-46079

CVE-2021-46079 - An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can…

exploitationpenetration-testingvulnerability-analysis+2
13 months ago
Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Html-Injection preview

Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Html-Injection

GitHubsanupl/vehicle-service-management-system-multiple-file-upload-leads-to-html-injection

CVE-2021-46079 - An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can…

exploitationpayload-generationpenetration-testing+3
3 months ago
wp-file-manager preview

wp-file-manager

GitHubrandomrobbiebf/wp-file-manager

wp-file-manager RCE

exploitationpayload-developmentpenetration-testing+1
95 years ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4793 years ago
snallygaster preview

snallygaster

GitHubhannob/snallygaster

Tool to scan for secret files on HTTP servers

information-gatheringreconnaissancevulnerability-scanners+1
2.1k6 months ago
Farmer preview

Farmer

GitHubmdsecactivebreach/farmer

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

information-gatheringlateral-movementpassword-attacks+4
4285 years ago
collision-webshell preview

collision-webshell

GitHubphith0n/collision-webshell

A webshell and a normal file that have the same MD5

cryptographyeducationpayload-development+2
4104 years ago
skyhook preview

skyhook

GitHubblackhillsinfosec/skyhook

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

data-exfiltrationids-ips-evasionred-teaming+1
2882 years ago
Metadata-Attacker preview

Metadata-Attacker

GitHubrub-nds/metadata-attacker

A tool to generate media files with malicious metadata

information-gatheringpayload-generationpenetration-testing+1
1287 years ago
CVE-2025-68461 preview

CVE-2025-68461

GitHubgotr00t0day/cve-2025-68461

A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.

information-gatheringpenetration-testingreconnaissance+3
78 months ago
faraday_zap preview

faraday_zap

GitHubinfobyte/faraday_zap

Zap Extension for collaboration in Faraday

api-security-testingpenetration-testingvulnerability-scanners+2
26 months ago
CVE-2021-31589 preview

CVE-2021-31589

GitHubkarthi-the-hacker/cve-2021-31589

Lightweight CLI scanner for CVE-2021-31589 that checks single or multiple URLs for the vulnerability, outputting results to a file for bug bounty and…

information-gatheringpenetration-testingreconnaissance+3
13 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubzam89/cve-2024-24919

Simple POC Python script that check & leverage Check Point CVE-2024-24919 vulnerability (Wrong Check Point)

exploitationinformation-gatheringpenetration-testing+3
42 years ago
Previous1234…28Next