Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
arsenal preview

arsenal

GitHuborange-cyberdefense/arsenal

Arsenal is just a quick inventory and launcher for hacking programs

command-and-controldns-analysisexploitation+6
3.8k
1 year ago
Adrenaline preview

Adrenaline

GitHubatomiczsec/adrenaline

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

command-and-controldefensive-toolsinformation-gathering+7
31612 days ago
porterminal preview

porterminal

GitHublyehe/porterminal

Quick n' dirty web/mcp terminal tunneling your phone & pc

command-and-controlpenetration-testingred-teaming+3
29714 days ago
Burp2Malleable preview

Burp2Malleable

GitHubcodextf2/burp2malleable

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

command-and-controlids-ips-evasionpayload-development+2
4183 years ago
ycsm preview

ycsm

GitHubinfosecn1nja/ycsm

This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools…

anti-botcommand-and-controlids-ips-evasion+2
867 years ago
Invoke-SelfSignedWebRequest preview

Invoke-SelfSignedWebRequest

GitHub0sm0s1z/invoke-selfsignedwebrequest

This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and press on with…

command-and-controlids-ips-evasionpenetration-testing+4
129 years ago
CVE-2017-0199 preview

CVE-2017-0199

GitHubexploit-install/cve-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could…

command-and-controlexploitationpayload-development+3
79 years ago
log4j-rce-test preview

log4j-rce-test

GitHubjeffli1024/log4j-rce-test

Quick test environment for CVE-2021-44228 Log4j RCE vulnerability with a built-in exploit server and customizable payload execution.

command-and-controlexploitationpayload-generation+2
24 years ago
cve-2021-26084-confluence preview

cve-2021-26084-confluence

GitHubglennpegden2/cve-2021-26084-confluence

A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.

command-and-controlexploitationpenetration-testing+2
14 years ago
omigod preview

omigod

GitHubgoofsec/omigod

Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go.

command-and-controlexploitationpenetration-testing+2
14 years ago
msfpc preview

msfpc

GitHubg0tmi1k/msfpc

MSFvenom Payload Creator (MSFPC)

command-and-controlexploit-frameworkspayload-development+5
1.3k5 years ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9623 days ago
CobaltStrike-BOF preview

CobaltStrike-BOF

GitHubyaxser/cobaltstrike-bof

Collection of beacon BOF written to learn windows and cobaltstrike

command-and-controleducationlateral-movement+3
3623 years ago
OSRipper preview

OSRipper

GitHubnoahoksuz/osripper

AV evading cross platform Backdoor and Crypter Framework with a integrated lightweight webUI

command-and-controleducationexploit-frameworks+5
3306 months ago
cve-2023-5044 preview

cve-2023-5044

GitHub4armed/cve-2023-5044

Go-based proof-of-concept exploit for CVE-2023-5044 in ingress-nginx, enabling authenticated remote command execution by creating crafted Kubernetes…

cloud-securitycommand-and-controlcontainer-security+5
22 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubprelearn-code/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

command-and-controlexploitationpayload-development+4
22 years ago
Webmin-1.580---file-show.cgi-Manual-Remote-Command-Execution-Non-Metasploit- preview

Webmin-1.580---file-show.cgi-Manual-Remote-Command-Execution-Non-Metasploit-

GitHubmarinovharisan/webmin-1.580---file-show.cgi-manual-remote-command-execution-non-metasploit-

Manual, non-Metasploit authenticated Remote Code Execution (RCE) exploit via the browser URL bar for Webmin 1.580 (CVE-2012-2982)

command-and-controlexploitationpenetration-testing+3
3 months ago
teamcity-exploit-cve-2023-42793 preview

teamcity-exploit-cve-2023-42793

GitHubswiftsecur/teamcity-exploit-cve-2023-42793

teamcity-exploit-cve-2023-42793

command-and-controlexploitationpenetration-testing+3
11 year ago