Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
155 results
CVE-2025-29927-scanner preview

CVE-2025-29927-scanner

GitHubnocomp/cve-2025-29927-scanner

python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927

information-gatheringpenetration-testingreconnaissance+3
1
1 year ago
cookiescanner preview

cookiescanner

GitHubsinkmanu/cookiescanner

Tool for check the cookie flag in multiple sites

information-gatheringvulnerability-scannersweb-security
2810 years ago
CVE-2020-0688-Scanner preview

CVE-2020-0688-Scanner

GitHubonsec-fr/cve-2020-0688-scanner

Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.

exploitationinformation-gatheringpenetration-testing+3
375 years ago
vhostawesome preview

vhostawesome

GitHubxssdoctor/vhostawesome

Concurrent virtual host scanner that brute-forces subdomains across multiple IPs on common web ports, filtering results by status codes and content…

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
372 years ago
EyeWitness preview

EyeWitness

GitHubredsiege/eyewitness

Automated web screenshot tool for reconnaissance, capturing site visuals, server headers, and identifying default credentials. Supports multiple…

information-gatheringosintpenetration-testing+2
5.8k8 months ago
CVE_2023_44487-Rapid_Reset preview

CVE_2023_44487-Rapid_Reset

GitHubmadhusudhan-in/cve_2023_44487-rapid_reset

A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over…

exploitationnetwork-securitypenetration-testing+3
11 month ago
CVE-2018-9995_dvr_credentials-dev_tool preview

CVE-2018-9995_dvr_credentials-dev_tool

GitHublikaifeng0/cve-2018-9995_dvr_credentials-dev_tool

Exploit tool for CVE-2018-9995 that extracts credentials from exposed DVR devices via HTTP request with cookie bypass, targeting multiple vendor…

exploitationinformation-gatheringiot-security+3
7 years ago
CVE-2018-9995_dvr_credentials preview

CVE-2018-9995_dvr_credentials

GitHubbatmoshka55/cve-2018-9995_dvr_credentials

Exploit tool for CVE-2018-9995 that retrieves DVR credentials via crafted HTTP request, targeting multiple DVR vendors for security testing.

exploitationinformation-gatheringiot-security+3
1 year ago
Logsensor preview

Logsensor

GitHubmr-robert0/logsensor

A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanning

information-gatheringpenetration-testingvulnerability-scanners+1
5254 years ago
url-status-checker preview

url-status-checker

GitHubblack-scorp10/url-status-checker

Async Python CLI tool for bulk URL status checking with color-coded HTTP response categorization, IP tracking, and redirect following for web service…

general-purpose-utilitiesinformation-gatheringweb-security
521 year ago
CVE-2025-30208 preview

CVE-2025-30208

GitHub0xshaheen/cve-2025-30208

Scanner for CVE-2025-30208 in Vite Dev Server, supporting single and mass URL scanning with multiple payloads, multi-threading, and vulnerable URL…

educationexploitationpenetration-testing+3
1 year ago
CVE-2017-9841 preview

CVE-2017-9841

GitHubjoelindra/cve-2017-9841

Tool designed to scan a list of websites for a known vulnerability in the PHPUnit framework, specifically the CVE-2017-9841 vulnerability.

exploitationinformation-gatheringpenetration-testing+3
13 months ago
PY-Log4j-RCE-Scanner preview

PY-Log4j-RCE-Scanner

GitHubmrharshvardhan/py-log4j-rce-scanner

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

dns-analysisexploitationreconnaissance+3
43 years ago
xurlfind3r preview

xurlfind3r

GitHubhueristiq/xurlfind3r

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

information-gatheringosintpenetration-testing+2
7209 months ago
deadfinder preview

deadfinder

GitHubhahwul/deadfinder

Fast CLI tool to scan websites, sitemaps, and URL lists for broken links, with concurrent workers, coverage reporting, and multiple output formats.

crawlerinformation-gatheringweb-security
18214h 44m ago
barrido preview

barrido

GitLabzer1t0/barrido

Tool to discover paths in web applications

fuzzinginformation-gatheringreconnaissance+2
22 years ago
autowpscan preview

autowpscan

GitHubpassword123456/autowpscan

Automated WordPress vulnerability scanner that processes multiple sites concurrently using wpscan, analyzes results, and sends summaries via Telegram.

information-gatheringvulnerability-scannersweb-security
12 years ago
scenester preview

scenester

GitHubnccgroup/scenester

A tool to visually snapshot a website by supplying multiple user-agent. Designed to aid in discovery of different entry points into an application.

information-gatheringosintpenetration-testing+2
3110 years ago
Previous12…9Next