Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
161 results
rengine preview

rengine

GitHubyogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

crawlerdns-subdomain-enumerationinformation-gathering+9
8.9k
10 months ago
flask_heroku_redirector preview

flask_heroku_redirector

GitHubkillswitch-gui/flask_heroku_redirector

flask heroku C2 redirector template

cloud-securitycommand-and-controlpenetration-testing+3
119 years ago
flask_appengine_redirector preview

flask_appengine_redirector

GitHubkillswitch-gui/flask_appengine_redirector

Google App Engine Flask C2 redirector

cloud-securitycommand-and-controlpenetration-testing+2
89 years ago
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubw2hcorp/cve-2025-29927-poc

Here is a simple but effective exploit for CVE-2025-29927.

exploitationpenetration-testingred-teaming+3
11 year ago
pwnlift preview

pwnlift

GitHubrasta-mouse/pwnlift

Easy peasy file uploads

data-exfiltrationpenetration-testingremote-access-tool+2
433 months ago
pingap preview

pingap

GitHubvicanso/pingap

A reverse proxy like nginx, built on pingora, simple and efficient.

api-securityauthenticationauthentication-authorization+4
1.4k2h 52m ago
BurpBounty preview

BurpBounty

GitHubwagiro/burpbounty

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and…

penetration-testingvulnerability-scannersweb-security
1.8k3 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubbytenull00/cve-2024-24919

Scans multiple URLs for the CVE-2024-24919 vulnerability in Check Point products, providing a quick and simple batch-checking script.

exploitationpenetration-testingreconnaissance+2
32 years ago
CVE-2025-55315-Scanner-Monitor preview

CVE-2025-55315-Scanner-Monitor

GitHubjlinebau/cve-2025-55315-scanner-monitor

Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitors

educationnetwork-securitypacket-sniffing-analysis+3
211 months ago
CVE-2023-44061 preview

CVE-2023-44061

GitHubsoundarxploit/cve-2023-44061

CVE-2023-44061 - Simple and Nice Shopping Cart Script V1.0

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
sdproxy preview

sdproxy

GitHubcbuijs/sdproxy

DNS Proxy that is simple and fast with not so simple features. Focused on routed DNS forwarding, filtering and parental control.

anomaly-detectiondefensive-toolsdns-analysis+7
555 days ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
awesome-rust-security preview

awesome-rust-security

GitHubosirislab/awesome-rust-security

Curated list of awesome projects and resources related to Rust and computer security

binary-analysiscloud-securitycryptography+9
6082 years ago
ExchangeFinder preview

ExchangeFinder

GitHubmhaskar/exchangefinder

Find Microsoft Exchange instance for a given domain and identify the exact version

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
1904 years ago
vaf preview

vaf

GitHubandreiverse/vaf

Multi-threaded web fuzzer for URL path, HTTP header, and POST data brute-forcing with proxy support, status code filtering, and reflexive content…

fuzzingpenetration-testingvulnerability-scanners+1
3194 years ago
CVE-2025-9784 preview

CVE-2025-9784

GitHubdrackyjr/cve-2025-9784

Bash script to test for CVE-2025-9784 HTTP/2 DoS vulnerability in Undertow servers. Measures baseline response times, simulates rapid stream resets,…

network-securitypenetration-testingvulnerability-analysis+2
211 months ago
CVE-2020-18324 preview

CVE-2020-18324

GitHubhamm0nz/cve-2020-18324

Proof-of-concept exploit demonstrating a reflected XSS vulnerability in Subrion CMS 4.2.1 via the Kickstart template search parameter, enabling…

exploitationpenetration-testingvulnerability-analysis+2
14 years ago
CVE-2020-18325 preview

CVE-2020-18325

GitHubhamm0nz/cve-2020-18325

Proof-of-concept exploit for reflected XSS vulnerabilities in Subrion CMS v4.2.1 configuration panel, demonstrating JavaScript injection via POST…

educationexploitationpenetration-testing+3
4 years ago
Previous12…9Next