Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
74 results
CVE-2023-4357 preview

CVE-2023-4357

GitHubwinniezy/cve-2023-4357

Reproduction case for CVE-2023-4357, a Chrome XXE vulnerability enabling arbitrary file read, with proof-of-concept files and a hosted test page.

exploitationvulnerability-analysisweb-application-exploitation+1
2 years ago
CVE-2014-0160-Chrome-Plugin preview

CVE-2014-0160-Chrome-Plugin

GitHubmre-fog/cve-2014-0160-chrome-plugin

Deprecated Chrome plugin that checks websites for the Heartbleed vulnerability (CVE-2014-0160) via an API, with linked exploit code for educational…

curated-resourceseducationexploitation+2
3 years ago
heartbleedchecker-chrome preview

heartbleedchecker-chrome

GitHubroganartu/heartbleedchecker-chrome

Chrome extension that automatically checks visited sites for vulnerability to OpenSSL CVE-2014-0160

vulnerability-scannersweb-security
12 years ago
widevine-l3-decryptor preview
Archived

widevine-l3-decryptor

GitHubtomer8007/widevine-l3-decryptor

A Chrome extension that demonstrates bypassing Widevine L3 DRM

binary-analysiseducationencryption-decryption-tools+3
1.2k3 years ago
webrtc-ips preview

webrtc-ips

GitHubdiafygi/webrtc-ips

Demo: https://diafygi.github.io/webrtc-ips/

educationosintprivacy+1
3.5k11 years ago
Blind-XSS-Manager preview

Blind-XSS-Manager

GitHubseifelsallamy/blind-xss-manager

Never forget where you inject.

payload-generationpenetration-testingweb-application-exploitation+1
3051 year ago
s3cXSSer preview

s3cXSSer

GitHubs3c-krd/s3cxsser

This extension will help you to detect GET/POST based XSS vulnerability in any website easily

penetration-testingvulnerability-analysisweb-security+1
2453 years ago
debugHunter preview

debugHunter

GitHubdevploit/debughunter

Discover hidden debugging parameters and uncover web application secrets

ctfinformation-gatheringpenetration-testing+3
2498 months ago
Needle preview

Needle

GitHubhumblelad/needle

Instant access to you bug bounty submission dashboard on various platforms + publicly disclosed reports + #bugbountytip

information-gatheringpenetration-testingreconnaissance+2
266 years ago
CVE-2022-3656 preview

CVE-2022-3656

GitHubmomika233/cve-2022-3656

Proof-of-concept exploit for CVE-2022-3656, a Chrome/Chromium vulnerability enabling theft of sensitive files like encrypted wallets and cloud…

data-exfiltrationexploitationvulnerability-analysis+1
383 years ago
PenScope preview

PenScope

GitHubspider12223/penscope

Passive recon & attack surface mapper — zero requests sent

crawlerexploitationinformation-gathering+7
375 months ago
AMSIext preview

AMSIext

GitHubelevenpaths/amsiext

AMSIext

defensive-toolsdynamic-analysis-sandboxingmalware-analysis+2
66 years ago
CVE-2024-5274-Detection preview

CVE-2024-5274-Detection

GitHubalchemist3dot14/cve-2024-5274-detection

Guardian Code: A Script to Uncover CVE-2024-5274 Vulnerabilities

educationscripting-automationvulnerability-analysis+2
32 years ago
CVE-2014-0160-Chrome-Plugin preview

CVE-2014-0160-Chrome-Plugin

GitHubxyl2k/cve-2014-0160-chrome-plugin

Heartbleed

curated-resourceseducationexploitation+2
110 years ago
CVE-2026-11645 preview

CVE-2026-11645

GitHub0xblackash/cve-2026-11645

CVE-2026-11645

educationexploitationincident-response+3
13 months ago
CVE-2017-3078 preview

CVE-2017-3078

GitHubhomjxi0e/cve-2017-3078

Proof-of-concept exploit for CVE-2017-3078, a memory corruption vulnerability in Adobe Flash Player ATF module enabling arbitrary code execution on…

binary-exploitationexploitationinformation-gathering+2
9 years ago
CVE-2024-34582 preview

CVE-2024-34582

GitHubsilent6trinity/cve-2024-34582

Proof-of-concept for reflected XSS (CVE-2024-34582) in Sunhillo Rici5k/Sureline web servers via the userid_change parameter in /cgi/usrPasswd.cgi.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2021-21193 preview

CVE-2021-21193

GitHubmehrzad1994/cve-2021-21193

Educational presentation analyzing CVE-2021-21193, a use-after-free vulnerability in Google Chrome's Blink engine, including exploitation details and…

curated-resourceseducationpapers-research+2
4 years ago
Previous12345Next