Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5129 results
CVE-2026-85706 preview

CVE-2026-85706

GitHubbrigadeops32/cve-2026-85706

Python PoC exploiting CVE-2026-85706, an unauthenticated path traversal and arbitrary file read in GitLab CE/EE via the create-commit endpoint, with…

data-exfiltrationexploitationinformation-gathering+5
12h 46m ago
devin-cve48384-1789318364-1162143-parent preview

devin-cve48384-1789318364-1162143-parent

GitHubfishjojo1/devin-cve48384-1789318364-1162143-parent

Authorized reachability probe for CVE-2025-48384, used to verify whether a target is exposed to the vulnerability in a controlled testing context.

exploitationpenetration-testingreconnaissance+2
12h 44m ago
blitzstrike preview

blitzstrike

GitHubshinthink/blitzstrike

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…

exploitationinformation-gatheringpayload-generation+8
21 day ago
dig preview

dig

GitHubxsser/dig

macOS dig wrapper that appends spoofed local TXT records to DNS query output, designed to deceive LLM agents into performing automated penetration…

command-and-controldns-analysisinformation-gathering+3
331 day ago
nuclei-CVE-2025-24813 preview

nuclei-CVE-2025-24813

GitHubsebastianmautner/nuclei-cve-2025-24813

University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting…

exploitationpenetration-testingreconnaissance+4
1 day ago
CVE-2026-32202 preview

CVE-2026-32202

GitHubf0xox/cve-2026-32202

Technical analysis of CVE-2026-32202, a zero-click NTLM credential coercion via crafted .lnk Control Panel applet items in Windows Explorer.

exploitationinformation-gatheringpapers-research+4
2 months ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubsolivaquaant/cve-2026-85706

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

data-exfiltrationexploitationinformation-gathering+7
2 days ago
ADRecon preview

ADRecon

GitHubadrecon/adrecon

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

defensive-toolsdigital-forensicsincident-response+6
9801 year ago
CVE-2026-80099 preview

CVE-2026-80099

GitHubwayang1337/cve-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

exploitationinformation-gatheringpassword-attacks+7
1 day ago
gitlab-cve-2026-85706-ioc preview

gitlab-cve-2026-85706-ioc

GitHubjithinkrishnanrs/gitlab-cve-2026-85706-ioc

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE…

defensive-toolsincident-responseinformation-gathering+8
11 day ago
GitLabSniper preview

GitLabSniper

GitHubynsmroztas/gitlabsniper

Single-file Python scanner and exploit for CVE-2026-85706, an unauthenticated arbitrary file read in self-managed GitLab CE/EE, with project…

data-exfiltrationexploitationinformation-gathering+6
22 days ago
TornadoRevC2 preview

TornadoRevC2

GitHubkamalx06/tornadorevc2

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

command-and-controlinformation-gatheringlateral-movement+8
242 days ago
cve-2026-85706 preview

cve-2026-85706

GitHubguneykabel/cve-2026-85706

Python PoC exploit for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE via Workhorse path-encoding bypass, with writeup and…

exploitationinformation-gatheringpenetration-testing+4
42 days ago
CVE-2026-85612 preview

CVE-2026-85612

GitHubhotplugin0x01/cve-2026-85612

OpenPanel Unauthenticated Server-Side Request Forgery (SSRF)

exploitationinformation-gatheringpapers-research+2
2 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubmhtsec/cve-2026-85706

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

data-exfiltrationexploitationinformation-gathering+5
12 days ago
CVE-2026-85706-PoC preview

CVE-2026-85706-PoC

GitHubsolivaquaant/cve-2026-85706-poc

PoC for CVE-2026-85706: GitLab CE/EE unauthenticated arbitrary local file read

data-exfiltrationexploitationinformation-gathering+4
2 days ago
disclosure-check preview

disclosure-check

GitHubgmh5225/disclosure-check

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

defensive-toolsinformation-gatheringosint+4
3 years ago
ThreatLens preview

ThreatLens

GitHubabdaullahag/threatlens

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

defensive-toolsincident-responseinformation-gathering+7
83 days ago
Previous12…100Next