Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
74 results
ChangeTower preview

ChangeTower

GitHubdc4ts/changetower

Lightweight web page change monitor written in Go. Detects updates on target URLs and sends notifications via Telegram or other services, ideal for…

crawlerinformation-gatheringweb-security
415 years ago
CVE-2026-35584 preview

CVE-2026-35584

GitHubspoo1k/cve-2026-35584

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

exploitationinformation-gatheringpenetration-testing+3
5 months ago
CVE-2022-0739-Exploitation preview

CVE-2022-0739-Exploitation

GitHubmanjen1218/cve-2022-0739-exploitation

Exploit for CVE-2022-0739 targeting unauthenticated SQL injection in BookingPress WordPress plugin versions before 1.0.11 via the…

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
shellshock_crawler preview

shellshock_crawler

GitHub352926/shellshock_crawler

Using google to scan sites for "ShellShock" (CVE-2014-6271)

exploitationinformation-gatheringosint+3
12 years ago
CVE-2023-33405 preview

CVE-2023-33405

GitHubhacip/cve-2023-33405

Proof-of-concept exploit for an open redirect vulnerability (CVE-2023-33405) in BlogEngine.NET CMS versions 3.3.8.0 and earlier, demonstrating…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2020-3187 preview

CVE-2020-3187

GitHubsujaygr8/cve-2020-3187

Proof-of-concept exploit for CVE-2020-3187 targeting Cisco ASA/FTD session password disclosure via crafted HTTP cookie header.

exploitationpenetration-testingvulnerability-analysis+2
5 years ago
avo-CVE-2024-22411 preview

avo-CVE-2024-22411

GitHubtamaloa/avo-cve-2024-22411

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.

code-analysisexploitationpenetration-testing+2
2 years ago
parameth preview
Archived

parameth

GitHubmak-/parameth

This tool can be used to brute discover GET and POST parameters

information-gatheringpenetration-testingreconnaissance+3
1.4k7 years ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k2 years ago
wraith preview

wraith

GitHubarcanum-sec/wraith

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

command-and-controleducationexploitation+6
1461 month ago
CVE-2026-76565 preview

CVE-2026-76565

GitHubtoanln-cov/cve-2026-76565

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

exploitationpapers-researchvulnerability-analysis+2
1 month ago
getrails preview

getrails

GitHubjul10l1r4/getrails

Get trails lib: Get all urls indexed of target

dns-subdomain-enumerationinformation-gatheringosint+1
4 years ago
Http11Probe preview

Http11Probe

GitHubmda2av/http11probe

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

api-security-testingfuzzingmisconfiguration+2
302 days ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
CVE-2025-10035_GoAnywhere preview

CVE-2025-10035_GoAnywhere

GitHuborange0mint/cve-2025-10035_goanywhere

CVE-2025-10035_GoAnywhere Get RCE

exploitationinformation-gatheringpenetration-testing+3
0 years ago
HotelDruid-CVE-2021-42948 preview

HotelDruid-CVE-2021-42948

GitHubdhammon/hoteldruid-cve-2021-42948

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
SocialPwned preview
Archived

SocialPwned

GitHubmrtuxx/socialpwned

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

email-harvestinginformation-gatheringosint+5
1.3k1 year ago
DSSS preview

DSSS

GitHubstamparm/dsss

Damn Small SQLi Scanner

vulnerability-scannersweb-application-exploitationweb-security
8801 month ago
Previous12345Next