Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
106 results
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
12.0k15h 56m ago
Red-Team-GOAD-Lab-Proxmox preview

Red-Team-GOAD-Lab-Proxmox

GitHubpho5nix/red-team-goad-lab-proxmox

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

adversarial-attackcommand-and-controldefensive-tools+7
286 days ago
mora-hwbp preview

mora-hwbp

GitHubdovughs/mora-hwbp

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

adversarial-attackdebuggersdefensive-tools+3
189 days ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

adversarial-attackcommand-and-controleducation+9
1.1k12 days ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k25 days ago
caldera preview

caldera

GitHubapache/caldera

Automated Adversary Emulation Platform

adversarial-attackcommand-and-controlctf+7
7.3k1 month ago
gradient-untangler preview

gradient-untangler

GitLabwattocyber/gradient-untangler

Local white-box gradient attacks for open-weight LLMs: GCG/PEZ suffix search, layer saliency, weight snapshots, and rank-1 suffix-to-delta fitting…

adversarial-attackai-securitymachine-learning+1
1 month ago
NoiseHound preview

NoiseHound

GitHubwarpedatom/noisehound

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

adversarial-attackdefensive-toolslateral-movement+4
671 month ago
lldp preview

lldp

GitHubwhispergate/lldp

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

adversarial-attackcommand-and-controlids-ips-evasion+1
231 month ago
DutchOven preview

DutchOven

GitHubloosehose/dutchoven

Application-scoped Windows network brownouts in native C and BOF form

adversarial-attackchaos-engineeringnetwork-security+2
231 month ago
xspawn preview

xspawn

GitHubcenobyte-vincit/xspawn

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

adversarial-attackids-ips-evasionpersistence-mechanisms+2
1 month ago
printnightmare-detection-lab preview

printnightmare-detection-lab

GitHubjoertx07/printnightmare-detection-lab

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

adversarial-attackeducationexploitation+6
1 month ago
CVE-2026-22007-NTP-monlist-Amplification-over-IPv6 preview

CVE-2026-22007-NTP-monlist-Amplification-over-IPv6

GitHubgeorge0papasotiriou/cve-2026-22007-ntp-monlist-amplification-over-ipv6

Python PoC for CVE-2026-22007: NTP monlist amplification over IPv6, including a simulated vulnerable server and spoofed UDP reflection attack.

adversarial-attackexploitationmisconfiguration+3
2 months ago
CVE-2026-21010-VoIP-SIP-Digest-Authentication-Replay preview

CVE-2026-21010-VoIP-SIP-Digest-Authentication-Replay

GitHubgeorge0papasotiriou/cve-2026-21010-voip-sip-digest-authentication-replay

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

adversarial-attackauthentication-authorizationexploitation+3
2 months ago
CVE-2026-7070-RDP-Clipboard-Hijacking-via-Virtual-Channel-Injection preview

CVE-2026-7070-RDP-Clipboard-Hijacking-via-Virtual-Channel-Injection

GitHubgeorge0papasotiriou/cve-2026-7070-rdp-clipboard-hijacking-via-virtual-channel-injection

CVE-2026-7070 PoC for RDP clipboard hijacking via virtual channel injection; includes simulated server and exploit script for data theft/credential…

adversarial-attackdata-exfiltrationexploitation+3
2 months ago
CVE-2026-6060-QUIC-Handshake-Amplification-via-Address-Validation-Bypass preview

CVE-2026-6060-QUIC-Handshake-Amplification-via-Address-Validation-Bypass

GitHubgeorge0papasotiriou/cve-2026-6060-quic-handshake-amplification-via-address-validation-bypass

Educational Python PoC for a QUIC address-validation bypass that triggers handshake amplification, including vulnerable server simulation and attack…

adversarial-attackeducationexploitation+2
2 months ago
CVE-2026-54121-CertiGhost preview

CVE-2026-54121-CertiGhost

GitHubmarcgoam/cve-2026-54121-certighost

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

adversarial-attackauthentication-authorizationexploitation+4
112 months ago
project_mantis preview

project_mantis

GitHubpasquini-dario/project_mantis

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

adversarial-attackai-securitynetwork-security+4
1232 months ago
Previous123456Next