Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
flawfinder preview

flawfinder

GitHubdavid-a-wheeler/flawfinder

a static analysis tool for finding vulnerabilities in C/C++ source code

code-analysisdevsecopsstatic-analysis+2
5824 months ago
Suborner preview

Suborner

GitHubr4wd3r/suborner

Creates invisible Windows accounts with administrative privileges via direct SAM manipulation and RID hijacking, bypassing standard user management…

persistence-mechanismspost-exploitationprivilege-escalation+1
4701 year ago
wordpress-really-simple-security-authn-bypass-exploit preview

wordpress-really-simple-security-authn-bypass-exploit

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-exploit

Python exploit for CVE-2024-10924 authentication bypass in Really Simple Security < 9.1.2. Enables unauthenticated login as any existing WordPress…

authentication-authorizationexploitationpenetration-testing+3
201 year ago
vsFTP-2.3.4-Remote-Root-Shell-Exploit preview

vsFTP-2.3.4-Remote-Root-Shell-Exploit

GitHubgill-singh-a/vsftp-2.3.4-remote-root-shell-exploit

A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4

command-and-controlexploitationpayload-development+3
22 years ago
Malbait preview

Malbait

GitHubbatchmcnulty/malbait

Simple TCP/UDP honeypot implemented in Perl

defensive-toolsfuzzingintrusion-detection+3
92 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubmrp4nda1337/cve-2023-23752

simple program for joomla scanner CVE-2023-23752 with target list

educationexploitationinformation-gathering+3
3 years ago
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
2993 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubz3n70/cve-2023-23752

simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose

educationexploitationpenetration-testing+2
183 years ago
deobf-Arxan-Deob-C preview

deobf-Arxan-Deob-C

GitHubgmh5225/deobf-arxan-deob-c

Simple C program to quickly deobfuscate windows executables protected with Arxan.

binary-analysisdefensive-toolsmalware-analysis+1
153 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubz3n70/cve-2020-5902

BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerability

exploitationpenetration-testingvulnerability-analysis+1
24 years ago
CVE-2022-30190-Follina-Patch preview

CVE-2022-30190-Follina-Patch

GitHubsuenerve/cve-2022-30190-follina-patch

The CVE-2022-30190-follina Workarounds Patch

configuration-auditingexploitationincident-response+2
24 years ago
lsm_bpf_check_argc0 preview
Archived

lsm_bpf_check_argc0

GitHubevdenis/lsm_bpf_check_argc0

LSM BPF module to block pwnkit (CVE-2021-4034) like exploits

defensive-tools
214 years ago
Log4j_Vulnerability_Demo preview

Log4j_Vulnerability_Demo

GitHubchandanshastri/log4j_vulnerability_demo

A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )

educationexploitationlog-analysis+2
34 years ago
CVE-2021-43798 preview

CVE-2021-43798

GitHubz3n70/cve-2021-43798

Simple program for exploit grafana

exploitationinformation-gatheringpenetration-testing+2
54 years ago
CVE-2021-41277 preview

CVE-2021-41277

GitHubz3n70/cve-2021-41277

simple program for exploit metabase

exploitationinformation-gatheringpenetration-testing+2
54 years ago
http_bridge preview

http_bridge

GitHubalejandro-llanes/http_bridge

SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…

ids-ips-evasionred-teamingweb-proxies-interception
85 years ago
protobuf-inspector preview

protobuf-inspector

GitHubmildsunrise/protobuf-inspector

🕵️ Tool to reverse-engineer Protocol Buffers with unknown definition

binary-analysisreverse-engineeringutilities-frameworks
1.1k5 years ago
Remot3d preview

Remot3d

GitHubkeepwannabe/remot3d

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to control server by backdoors

exploitationpayload-generationpenetration-testing+2
2826 years ago
Previous12Next