Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2268 results
cve-2026-64560-a16 preview

cve-2026-64560-a16

GitHubbecome-illusory/cve-2026-64560-a16

CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port

android-securitybinary-exploitationexploitation+8
6 days ago
wappalyzergo preview

wappalyzergo

GitHubprojectdiscovery/wappalyzergo

A high performance go implementation of Wappalyzer Technology Detection Library

crawlerinformation-gatheringreconnaissance+2
1.1k5 days ago
NagiosXI-RCE-all-version-CVE-2021-40345 preview

NagiosXI-RCE-all-version-CVE-2021-40345

GitHubarianeblow/nagiosxi-rce-all-version-cve-2021-40345

RFI to RCE Nagios/NagiosXI exploitation

exploitationpayload-generationpenetration-testing+3
4 years ago
nmap preview

nmap

GitHubullaakut/nmap

Idiomatic Go library for invoking a network scanner binary, enabling host discovery, port scanning, service/OS detection, and scripted vulnerability…

information-gatheringnetwork-mappingnetwork-security+3
1.1k5 days ago
play-go-copy-fail-cve-2026-31431 preview

play-go-copy-fail-cve-2026-31431

GitHubimkk000/play-go-copy-fail-cve-2026-31431

Educational Go implementation of a Linux syscall-based exploit for CVE-2026-31431, demonstrating payload crafting and PTY upgrade techniques for…

binary-exploitationeducationexploitation+1
5 months ago
CVE-2022-24715-go preview

CVE-2022-24715-go

GitHubd4rkb0n3/cve-2022-24715-go

Go-based exploit for Icinga Web 2 (CVE-2022-24715) enabling remote code execution against vulnerable instances. Port of original Python PoC.

exploitationpenetration-testingred-teaming+2
2 years ago
jfscan preview
Archived

jfscan

GitHubnullt3r/jfscan

JF⚡can - Super fast port scanning & service discovery using Masscan and Nmap. Scan large networks with Masscan and use Nmap's scripting abilities to…

information-gatheringnetwork-mappingpenetration-testing+3
6687 months ago
bettercap preview

bettercap

GitHubbettercap/bettercap

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

bluetooth-securitydata-exfiltrationfingerprint-spoofing+16
20.0k1 month ago
cve-2023-38646-metabase-ReverseShell preview

cve-2023-38646-metabase-ReverseShell

GitHubany3ite/cve-2023-38646-metabase-reverseshell

Go-based exploit for CVE-2023-38646 in Metabase, enabling remote code execution and reverse shell connection to an attacker-controlled host.

exploitationpayload-generationpenetration-testing+3
3 years ago
CVE-2023-44761_ConcreteCMS-Stored-XSS---Forms preview

CVE-2023-44761_ConcreteCMS-Stored-XSS---Forms

GitHubsromanhu/cve-2023-44761_concretecms-stored-xss---forms

Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Form of the…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4081 year ago
portclue preview

portclue

GitHubpbxqdown/portclue

Explain why a Linux TCP port may or may not be reachable

configuration-auditingcontainer-securitydefensive-tools+3
33 days ago
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.3k1 day ago
chisel preview

chisel

GitHubjpillora/chisel

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

command-and-controldata-exfiltrationgeneral-purpose-utilities+8
16.6k1 month ago
nmap-vulners preview

nmap-vulners

GitHubvulnerscom/nmap-vulners

Nmap NSE script that queries the Vulners API to identify known vulnerabilities (CVEs) for detected network services, enhancing standard port scanning…

information-gatheringnetwork-securityvulnerability-analysis+1
3.5k4 days ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
Stowaway preview

Stowaway

GitHubph4ntonn/stowaway

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

command-and-controlencryption-decryption-toolslateral-movement+3
3.4k7 months ago
ADB-Toolkit preview

ADB-Toolkit

GitHubashwin990/adb-toolkit

ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!

android-securityexploit-frameworksinformation-gathering+3
2.0k3 years ago
Previous123…100Next