Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
KnockOutlook preview

KnockOutlook

GitHubeksperience/knockoutlook

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

data-exfiltrationemail-securityinformation-gathering+2
206
4 years ago
cve-2026-54316-lab preview

cve-2026-54316-lab

GitHubinertfluid/cve-2026-54316-lab

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

ctfdata-exfiltrationeducation+5
2 months ago
BlockGuard preview

BlockGuard

GitHubm2l33k/blockguard

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

authentication-authorizationconfiguration-auditingdata-exfiltration+4
6 months ago
Fireaway preview

Fireaway

GitHubtcstool/fireaway

Next Generation Firewall Audit and Bypass Tool

data-exfiltrationids-ips-evasionnetwork-security+1
2679 years ago
moukthar preview

moukthar

GitHubtomiwa-ot/moukthar

Android remote administration tool

android-securitycommand-and-controldata-exfiltration+6
6769 months ago
RingReaper preview

RingReaper

GitHubmatheuzsecurity/ringreaper

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

adversarial-attackcommand-and-controldata-exfiltration+5
3851 year ago
CVE-2025-58443 preview

CVE-2025-58443

GitHubcasp3r0x0/cve-2025-58443

FOGProject Authentication bypass CVE-2025-58443 Exploit

database-securitydata-exfiltrationexploitation+3
20 years ago
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.8k6 months ago
DLPwn preview

DLPwn

GitHubgryfman/dlpwn

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

bluetooth-securitycommand-and-controldata-exfiltration+5
246 months ago
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis preview

RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis

GitHubkaandemir993/redline-stealer-c2-defender-bypass-payload-analysis

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

command-and-controldata-exfiltrationmalware-analysis+4
119 days ago
firefox_tunnel preview
Archived

firefox_tunnel

GitHubconviso-archives/firefox_tunnel

Browser-based C2 tunnel that exfiltrates payloads through Firefox's cookie.sqlite and auto-submitting HTML/JS, enabling stealthy firewall bypass for…

command-and-controldata-exfiltrationids-ips-evasion+5
618 years ago
iodine preview

iodine

GitHubyarrick/iodine

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

command-and-controldata-exfiltrationids-ips-evasion+4
8.0k0 years ago
CVE-2025-24104 preview

CVE-2025-24104

GitHubifpdz/cve-2025-24104

Technical writeup of CVE-2025-24104: an iOS sandbox escape via symlink validation bypass in backup restoration, enabling arbitrary file reads outside…

binary-exploitationdata-exfiltrationexploitation+4
521 year ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
27 months ago
PhoneSploit-Pro preview

PhoneSploit-Pro

GitHubazeemidrisi/phonesploit-pro

An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.

android-securitycommand-and-controldata-exfiltration+7
6.2k21 days ago
androrat preview

androrat

GitHubdesignativedave/androrat

Remote Administration Tool for Android devices

android-securitycommand-and-controldata-exfiltration+9
1.6k3 years ago
PhoneMonitor preview

PhoneMonitor

GitHubglobalpolicy/phonemonitor

A Remote Administration Tool for Android devices

android-securitycommand-and-controldata-exfiltration+3
2665 years ago
blue-pigeon preview

blue-pigeon

GitHubbluepigeonproject/blue-pigeon

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

android-securitybluetooth-securitycommand-and-control+4
565 years ago
Previous1234Next