Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
618 results
browsertunnel preview

browsertunnel

GitHubveggiedefender/browsertunnel

Surreptitiously exfiltrate data from the browser over DNS

data-exfiltrationdns-analysisred-teaming+1
422
6 years ago
PlasmaRAT preview

PlasmaRAT

GitHubmwsrc/plasmarat

Remote Access Trojan(RAT), Miner, DDoS

command-and-controldata-exfiltrationmalware-analysis+3
4069 years ago
rdroid preview

rdroid

GitHubhuntoai/rdroid

[Android RAT] Remotely manage your android phone using PHP Interface

android-securitycommand-and-controldata-exfiltration+3
2478 years ago
MAAD-AF preview

MAAD-AF

GitHubvectra-ai-research/maad-af

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

adversarial-attackcloud-securitydata-exfiltration+6
4318 months ago
pwnbin preview

pwnbin

GitHubkahunalu/pwnbin

Python Pastebin Webcrawler that returns list of public pastebins containing keywords

crawlerdata-exfiltrationinformation-gathering+1
4506 years ago
physmem2profit preview

physmem2profit

GitHubreverseclabs/physmem2profit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

data-exfiltrationdigital-forensicsmemory-forensics+4
4224 years ago
njRAT preview

njRAT

GitHubmwsrc/njrat

njRAT SRC Extract

command-and-controldata-exfiltrationexploitation+9
3149 years ago
ExtractBitlockerKeys preview

ExtractBitlockerKeys

GitHubp0dalirius/extractbitlockerkeys

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.

data-exfiltrationencryption-decryption-toolsinformation-gathering+1
4037 months ago
BetterBackdoor preview

BetterBackdoor

GitHubthatcherclough/betterbackdoor

A backdoor with a multitude of features.

command-and-controldata-exfiltrationpassword-cracking+4
2935 years ago
CallStranger preview

CallStranger

GitHubyunuscadirci/callstranger

Vulnerability checker for Callstranger (CVE-2020-12695)

data-exfiltrationdns-analysisiot-security+3
4035 years ago
XFLTReaT preview

XFLTReaT

GitHubearthquake/xfltreat

XFLTReaT tunnelling framework

data-exfiltrationnetwork-securitypenetration-testing+1
3316 years ago
FFM preview

FFM

GitHubjusticerage/ffm

Freedom Fighting Mode: open source hacking harness

command-and-controldata-exfiltrationinformation-gathering+6
3485 months ago
QRExfil preview

QRExfil

GitHubshell-company/qrexfil

This tool is a command line utility that allows you to convert any binary file into a QRcode movie. The data can then be reassembled visually…

data-exfiltrationred-teaming
2813 years ago
flashsploit preview

flashsploit

GitHubthewhiteh4t/flashsploit

Exploitation Framework for ATtiny85 Based HID Attacks

data-exfiltrationexploit-frameworkshardware-hacking+3
3626 years ago
van-gonography preview

van-gonography

GitHubjoshuakasa/van-gonography

Hide 🕵️‍♂️ your files of any type inside a image of your choice using steganography

cryptographydata-exfiltrationencryption-decryption-tools+3
44910 months ago
Bella preview

Bella

GitHub00xglitch/bella

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

command-and-controldata-exfiltrationids-ips-evasion+8
2053 years ago
RingReaper preview

RingReaper

GitHubmatheuzsecurity/ringreaper

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

adversarial-attackcommand-and-controldata-exfiltration+5
3861 year ago
EmbedPayloadInPng preview

EmbedPayloadInPng

GitHubmaldev-academy/embedpayloadinpng

Embed a payload inside a PNG file

cryptographydata-exfiltrationids-ips-evasion+2
3731 year ago
Previous1…252627…35Next