Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2902 results
Argus preview

Argus

GitHubjasonxtn/argus

The Ultimate Information Gathering Toolkit

crawlerdns-analysisemail-harvesting+7
4.1k9 months ago
CORStest preview

CORStest

GitHubrub-nds/corstest

A simple CORS misconfiguration scanner

misconfigurationpenetration-testingvulnerability-scanners+1
4246 years ago
GitDorker preview

GitDorker

GitHubobheda12/gitdorker

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

information-gatheringosintreconnaissance+2
2.6k5 years ago
CMSmap preview

CMSmap

GitHubdionach/cmsmap

CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

information-gatheringvulnerability-scannersweb-security
1.2k7 years ago
violent-python3 preview

violent-python3

GitHubeonraider/violent-python3

Source code for the book "Violent Python" by TJ O'Connor. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

bluetooth-securityeducationexploitation+8
1.1k25 days ago
Joomla-CVE-Detector-CVE-2022-27913- preview

Joomla-CVE-Detector-CVE-2022-27913-

GitHubcameron-coding-projects/joomla-cve-detector-cve-2022-27913-

Detect Joomla instances vulnerable to CVE-2022-27913 with a lightweight Python scanner for rapid identification and reporting.

information-gatheringreconnaissancevulnerability-analysis+2
110 months ago
CVE-2026-76581-Detector preview

CVE-2026-76581-Detector

GitHubhackersroot/cve-2026-76581-detector

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

curated-resourceseducationvulnerability-scanners+1
7 days ago
Spring4Shell preview

Spring4Shell

GitHubjashan-lefty/spring4shell

In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem…

defensive-toolseducationincident-response+3
1 year ago
blackhat-python3 preview

blackhat-python3

GitHubeonraider/blackhat-python3

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

code-analysiscryptographyeducation+8
2.4k3 years ago
JS-Secret-Hunter preview

JS-Secret-Hunter

GitHubsohelyousef/js-secret-hunter

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

crawlerinformation-gatheringpenetration-testing+3
7 months ago
CVE-2021-41773.git1 preview

CVE-2021-41773.git1

GitHubmightysai1997/cve-2021-41773.git1

Fast Python tool to test Apache path traversal vulnerability CVE-2021-41773 against a list of URLs, enabling bulk scanning for this specific exploit.

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12613 years ago
MasterHttpRelayVPN-RUST preview

MasterHttpRelayVPN-RUST

GitHubtherealaleph/masterhttprelayvpn-rust

Rust port of @masterking32's MasterHttpRelayVPN — all credit to @masterking32 for the original idea and Python implementation. Free DPI bypass via a…

dns-analysisweb-security
3.6k5 days ago
CVE-2024-28397-js2py-Sandbox-Escape preview

CVE-2024-28397-js2py-Sandbox-Escape

GitHubnaved124/cve-2024-28397-js2py-sandbox-escape

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…

binary-exploitationcode-analysiseducation+5
1 year ago
CVE-2026-Pending-Flask-Uploads-Path-Traversal-PoC preview

CVE-2026-Pending-Flask-Uploads-Path-Traversal-PoC

GitHubnicetop1027/cve-2026-pending-flask-uploads-path-traversal-poc

Demonstration of CWE-22 Path Traversal in Flask-Uploads 0.2.1. For educational and security research purposes only. Tested on Python 3.11.

educationexploitationpenetration-testing+3
7 months ago
panos-captive-portal-rce preview

panos-captive-portal-rce

GitHubridhinva/panos-captive-portal-rce

Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto…

information-gatheringnetwork-securitypenetration-testing+3
21 month ago
cve-2021-41773-source-code-analysis preview

cve-2021-41773-source-code-analysis

GitHubkunalkhandelwal-dev/cve-2021-41773-source-code-analysis

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

code-analysiseducationlabs-practice+2
1 month ago
Telstra-Cybersecurity-Virtual-Experience- preview

Telstra-Cybersecurity-Virtual-Experience-

GitHubbl34chig0/telstra-cybersecurity-virtual-experience-

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

educationincident-responselabs-practice+2
22 years ago
Previous1…456…100Next