Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
T-MAP preview

T-MAP

GitHubpwnhyo/t-map

Trajectory-aware evolutionary search framework for red-teaming LLM agents over MCP servers, generating adversarial prompts to map vulnerability…

adversarial-attackai-securitymachine-learning+3
18
5 months ago
trustmebro preview

trustmebro

GitHubdavidcarliez/trustmebro

Bypass llm guardrails by confusing it with fabricated tool output.

adversarial-attackai-securityexploitation+3
45314 days ago
CrystalPotato preview

CrystalPotato

GitHubricardojoserf/crystalpotato

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

adversarial-attackexploitationpenetration-testing+3
12023 days ago
CVE-2023-44487 preview

CVE-2023-44487

GitHubimabee101/cve-2023-44487

PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

adversarial-attackexploitationweb-application-exploitation+1
562 years ago
CVE-2026-23744-PoC preview

CVE-2026-23744-PoC

GitHubsonnelon/cve-2026-23744-poc

The poc of CVE-2026-23744

adversarial-attackexploitationpenetration-testing+1
1 month ago
PSBits preview

PSBits

GitHubgtworek/psbits

Simple (relatively) things allowing you to dig a bit deeper than usual.

adversarial-attackexploitationpenetration-testing+5
3.5k1 month ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k6 days ago
DiagTrackEoP preview

DiagTrackEoP

GitHubwh04m1001/diagtrackeop

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

adversarial-attackexploitationpenetration-testing+3
884 years ago
magicNetdefs preview

magicNetdefs

GitHubcrisprss/magicnetdefs

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

adversarial-attackauthenticationexploitation+3
494 years ago
AtomicTestHarnesses preview

AtomicTestHarnesses

GitHubredcanaryco/atomictestharnesses

Public Repo for Atomic Test Harness

adversarial-attackdefensive-toolspenetration-testing+1
2931 year ago
Windows preview

Windows

GitHubsleepthegod/windows

Windows And Ways To Break It

adversarial-attackexploitationpenetration-testing+3
987 months ago
linux_injector preview

linux_injector

GitHubnamazso/linux_injector

A simple ptrace-less shared library injector for x64 Linux

adversarial-attackpayload-developmentpenetration-testing+3
2953 years ago
poc-h2-CVE-2026-71554 preview

poc-h2-CVE-2026-71554

GitHubsunandm/poc-h2-cve-2026-71554

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

adversarial-attackapi-securityapi-security-testing+4
11 month ago
PSpersist preview

PSpersist

GitHubsaadahla/pspersist

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

adversarial-attackpenetration-testingpersistence-mechanisms+2
833 years ago
OwnershipStealer preview

OwnershipStealer

GitHubadpunisher/ownershipstealer

Command-line utility for Windows that enables SeTakeOwnershipPrivilege and modifies file ownership to the current user, granting access to otherwise…

adversarial-attackpenetration-testingpost-exploitation+2
283 years ago
Bin-Finder preview

Bin-Finder

GitHubkudaes/bin-finder

Detect EDR's exceptions by inspecting processes' loaded modules

adversarial-attackpenetration-testingreconnaissance+1
1332 years ago
NoFilter preview

NoFilter

GitHubdeepinstinct/nofilter

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

adversarial-attackexploitationpenetration-testing+3
3041 year ago
SspiUacBypass preview

SspiUacBypass

GitHubantoniococo/sspiuacbypass

Bypassing UAC with SSPI Datagram Contexts

adversarial-attackexploitationpenetration-testing+3
4752 years ago
Previous12Next