Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3225 results
vulnerable-bsr-lab-CVE-2023-6933 preview

vulnerable-bsr-lab-CVE-2023-6933

GitHubtrex96/vulnerable-bsr-lab-cve-2023-6933

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

educationexploit-frameworkslabs-practice+3
11 months ago
sk-cve-2026-26030-lab preview

sk-cve-2026-26030-lab

GitHubinertfluid/sk-cve-2026-26030-lab

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

ai-securitybinary-exploitationeducation+5
12 months ago
DorXNG preview

DorXNG

GitHubresearchanddestroy/dorxng

Next Generation DorX. Built by Dorks, for Dorks. 🤓

dns-subdomain-enumerationinformation-gatheringosint+3
1223 years ago
blackbird preview

blackbird

GitLabgcabc123/blackbird

An OSINT tool to search for accounts by username in social networks.

curated-resourceseducationinformation-gathering+3
13 years ago
cve-2020-0618 preview

cve-2020-0618

GitHubwortell/cve-2020-0618

CVE-2020-0618 Honeypot

incident-responseintrusion-detectionthreat-intelligence+2
306 years ago
gtfocli preview

gtfocli

GitHubcmd-tools/gtfocli

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

ctfinformation-gatheringpenetration-testing+1
191 year ago
ggshield preview

ggshield

GitHubgitguardian/ggshield

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

code-analysisdevsecopssecret-detection+1
2.0k4 days ago
CVE-2018-1058 preview

CVE-2018-1058

GitHubccchme/cve-2018-1058

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

database-securityeducationexploitation+3
3 months ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
8 months ago
awesome-password-cracking preview

awesome-password-cracking

GitHubn0kovo/awesome-password-cracking

A curated list of awesome tools, research, papers and other projects related to password cracking and password security.

curated-resourceseducationhash-analysis+3
1.1k1 month ago
pythia-sql-clairvoyance preview

pythia-sql-clairvoyance

GitHubrodhnin/pythia-sql-clairvoyance

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlerdevsecops+5
24 months ago
Leaktopus preview
Archived

Leaktopus

GitHubplaytikaoss/leaktopus

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

code-analysisdevsecopsincident-response+6
305 months ago
ADTrapper preview

ADTrapper

GitHubmhaggis/adtrapper

Hunt Smarter, Hunt Harder

anomaly-detectionauthenticationcloud-security+4
2005 months ago
neko preview

neko

GitHubm1k1o/neko

A self hosted virtual browser that runs in docker and uses WebRTC.

container-securityprivacyremote-access-tool+1
22.2k2 days ago
TraceTree preview

TraceTree

GitHubtejasprasad2008-afk/tracetree

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

container-securitydevsecopsdynamic-analysis-sandboxing+6
428 days ago
CVE-2025-9074-PoC preview

CVE-2025-9074-PoC

GitHubbridgeralderson/cve-2025-9074-poc

A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on…

container-escapeexploitationpenetration-testing+3
508 months ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubj3r1ch0123/cve-2025-9074

New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet

container-securityeducationexploitation+3
80 years ago
cve-2024-41110-checker preview

cve-2024-41110-checker

GitHubvvpoglazov/cve-2024-41110-checker

Parallel SSH-based scanner that detects CVE-2024-41110 in Docker installations, identifies vulnerable versions and AuthZ plugins, and generates a…

cloud-infrastructure-securityconfiguration-auditingcontainer-security+2
62 years ago
Previous12…100Next