Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
CVE-2026-24061 preview

CVE-2026-24061

GitHubobrunolima1910/cve-2026-24061

🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.

authenticationeducationexploitation+3
14h 33m ago
netwatch preview

netwatch

GitHubmatthart1983/netwatch

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

defensive-toolsdigital-forensicsdns-analysis+8
2.6k5 days ago
FMD Android preview

FMD Android

GitLabfmd-foss/fmd-android

Find your device and control it remotely. Works over SMS, instant messengers, or FMD Server's web interface. A secure open source alternative to…

android-securitydata-recoverydefensive-tools+3
5186 days ago
HoneyWire preview

HoneyWire

GitHubandreicscs/honeywire

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

container-securitydevsecopsincident-response+3
1021 month ago
CVE-2026-15282 preview

CVE-2026-15282

GitHubshinthink/cve-2026-15282

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

educationexploitationpayload-generation+5
1 month ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubsh4den/cve-2026-24061

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…

authenticationcommand-and-controleducation+7
61 month ago
CVE-2026-24061-PoC-Exploit preview

CVE-2026-24061-PoC-Exploit

GitHubtc4dy/cve-2026-24061-poc-exploit

Remote authentication bypass exploit for GNU inetutils-telnetd (CVE-2026-24061) using CRLF injection to gain instant root shell. Supports single/mass…

command-and-controlexploitationpayload-development+3
62 months ago
Adalanche preview

Adalanche

GitHublkarlslund/adalanche

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

penetration-testingreconnaissancered-teaming+1
2.2k3 months ago
honeypotscan preview

honeypotscan

GitHubteycir/honeypotscan

Free honeypot token scanner for Ethereum, Polygon & Arbitrum. Detect scam tokens before you buy. Instant analysis of smart contracts using 13…

api-securityeducationprivacy+3
105 months ago
gtfobins-cli preview

gtfobins-cli

GitHubt0thkr1s/gtfobins-cli

Search for Unix binaries that can be exploited to bypass system security restrictions.

binary-exploitationinformation-gatheringpenetration-testing+2
1456 months ago
CVE-2025-60719-AFD.SYS preview

CVE-2025-60719-AFD.SYS

GitHubakamai/cve-2025-60719-afd.sys
ai-assisted-reversingbinary-exploitationeducation+3
48 months ago
OWASP-WSTG-Rag preview

OWASP-WSTG-Rag

GitHubzilbonn/owasp-wstg-rag

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

ai-securityapi-security-testingauthentication+8
228 months ago
BurpSuite-Grand-Master-Tools preview

BurpSuite-Grand-Master-Tools

GitHubnu11secur1ty/burpsuite-grand-master-tools

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

penetration-testingreconnaissancescripting-automation+3
29 months ago
whatsapp-census preview

whatsapp-census

GitHubsbaresearch/whatsapp-census
educationinformation-gatheringmobile-security+4
4039 months ago
CSV-Injection-in-Instant-Developer-Foundation-25.0-PoC preview

CSV-Injection-in-Instant-Developer-Foundation-25.0-PoC

GitHubvaleriocassoni/csv-injection-in-instant-developer-foundation-25.0-poc

This repository contains a Proof of Concept (PoC) for a CSV Injection (Formula Injection) vulnerability (CVE-2025-60852) affecting applications built…

data-exfiltrationeducationexploitation+3
10 months ago
CVE-2025-51863 preview

CVE-2025-51863

GitHubsecsys-fdu/cve-2025-51863
exploitationphishing-toolsvulnerability-analysis+2
1 year ago
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
31 year ago
instant-appointment-arbitrary-file-upload preview

instant-appointment-arbitrary-file-upload

GitHubrandomrobbiebf/instant-appointment-arbitrary-file-upload

instant-appointment - Arbitrary File upload

exploitationpayload-generationpenetration-testing+3
1 year ago
Previous12Next