Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
74 results
GetDataReport preview

GetDataReport

GitHubpowerscript/getdatareport

Get information client with getdatareport (Plugin)

information-gatheringosintweb-security
259 years ago
POC_CVE-2026-35037 preview

POC_CVE-2026-35037

GitHubfineman999/poc_cve-2026-35037

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

educationexploitationlabs-practice+3
4 months ago
CVE-2026-37069 preview

CVE-2026-37069

GitHubjfs-jfs/cve-2026-37069

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…

information-gatheringmisconfigurationvulnerability-analysis+1
3 months ago
SQLi_Sleeps preview

SQLi_Sleeps

GitHubhernanrodriguez1/sqli_sleeps

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

penetration-testingweb-application-exploitationweb-security+1
1251 year ago
HttpStrike preview

HttpStrike

GitHubk3ystr0k3r/httpstrike

DDoS script meant to flood websites.

network-securitypenetration-testingred-teaming+2
53 years ago
HTC preview

HTC

GitHubwmasday/htc

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

exploitationiot-securitypassword-attacks+3
33 years ago
HTC preview

HTC

GitHubawesome-consumer-iot/htc

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

exploitationpassword-attacksreconnaissance+2
16 years ago
changedetection.io preview

changedetection.io

GitHubdgtlmoon/changedetection.io

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

crawlerinformation-gatheringosint+2
34.5k3 days ago
spider preview

spider

GitHubspider-rs/spider

Get web data for AI agents and LLMs

ai-securityanti-botcrawler+2
2.7k8 days ago
ParamPamPam preview

ParamPamPam

GitHubbo0om/parampampam

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

fuzzinginformation-gatheringweb-security
2764 years ago
openapi_security_scanner preview

openapi_security_scanner

GitHubngalongc/openapi_security_scanner

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

api-security-testingpenetration-testingvulnerability-scanners+1
1735 years ago
extended-ssrf-search preview

extended-ssrf-search

GitHubdamian89/extended-ssrf-search

Smart ssrf scanner using different methods like parameter brute forcing in post and get...

fuzzingpenetration-testingvulnerability-scanners+1
2775 years ago
CVE-2002-0748 preview

CVE-2002-0748

GitHubfauzanwijaya/cve-2002-0748

Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability

exploitationpenetration-testingvulnerability-analysis+1
3 years ago
CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat- preview

CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat-

GitHubtheopaid/cve-2026-66750-insufficient-access-controls-allow-for-unauthorized-file-downloads-let-s-chat-

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

authentication-authorizationeducationmisconfiguration+2
1 month ago
DirDar preview

DirDar

GitHubm4dm0e/dirdar

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

information-gatheringpenetration-testingvulnerability-scanners+1
4542 years ago
watchTowr-vs-Progress-ShareFile-CVE-2026-2699 preview

watchTowr-vs-Progress-ShareFile-CVE-2026-2699

GitHubwatchtowrlabs/watchtowr-vs-progress-sharefile-cve-2026-2699

Detection artifact for CVE-2026-2699 Progress ShareFile authentication bypass. Sends GET to /ConfigService/Admin.aspx to check vulnerability.

authenticationpenetration-testingvulnerability-analysis+1
36 months ago
CVE-2026-21440 preview

CVE-2026-21440

GitHubyou-ssef9/cve-2026-21440

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

information-gatheringreconnaissancevulnerability-analysis+1
18 months ago
Cybersecurity-Books preview

Cybersecurity-Books

GitHubzealraj/cybersecurity-books

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

curated-resourcesdigital-forensicseducation+6
6924 years ago
Previous12345Next