Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
4 days ago
powerview.py preview

powerview.py

GitHubaniqfakhrul/powerview.py

Powerview on steroids

dns-analysisexploitationinformation-gathering+7
9892 months ago
phantomrecon preview

phantomrecon

GitHubl33tdawg/phantomrecon

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

dns-analysisexploitationinformation-gathering+6
36 months ago
Collabfiltrator preview

Collabfiltrator

GitHub0xc01df00d/collabfiltrator

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

data-exfiltrationdns-analysisexploitation+3
2811 year ago
rosemary preview

rosemary

GitHubblue0x1/rosemary

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

command-and-controldns-analysislateral-movement+4
1219 days ago
DNS-Persist preview

DNS-Persist

GitHub0x09al/dns-persist

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

command-and-controldns-analysispayload-generation+5
2078 years ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysisinformation-gathering+4
3.9k1 year ago
PwnSTAR preview

PwnSTAR

GitHubsilverfoxx/pwnstar

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

captcha-bypassdns-analysisexploitation+7
2608 years ago
firepwner preview

firepwner

GitHubmattimustang/firepwner

Exploit for CVE-2015-6357 Cisco FireSIGHT Management Center Certificate Validation Vulnerability

command-and-controldns-analysisexploitation+4
610 years ago
nuclei-templates preview

nuclei-templates

GitHubprojectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

code-analysiscrawlercurated-resources+6
12.8k16h 52m ago
CVE-2026-41096 preview

CVE-2026-41096

GitHubm0n1x90/cve-2026-41096

CVE-2026-41096: Heap Overflow in the Windows DNS Client

binary-exploitationdns-analysisexploitation+3
33 months ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubobscura-cert/cve-2025-33073
authenticationcommand-and-controldns-analysis+7
11 year ago
cupntlm-Automated-Exploit-For-CVE-2025-33073- preview

cupntlm-Automated-Exploit-For-CVE-2025-33073-

GitHubegcupcake/cupntlm-automated-exploit-for-cve-2025-33073-

cupntlm

authenticationcommand-and-controldns-analysis+9
34 months ago
CVE-2016-2776 preview

CVE-2016-2776

GitHubinfobyte/cve-2016-2776

CVE-2016-2776

dns-analysisexploitationexploit-frameworks+2
279 years ago
metasploit-bailiwicked_domain-fix preview

metasploit-bailiwicked_domain-fix

GitHubhamlasiraj/metasploit-bailiwicked_domain-fix

Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)

dns-analysiseducationexploitation+3
10 years ago
cve-2022-24644 preview

cve-2022-24644

GitHubgar-re/cve-2022-24644
dns-analysisexploitationprivilege-escalation+3
13 years ago
CVE-2021-26295-- preview

CVE-2021-26295--

GitHubcoolyin001/cve-2021-26295--

CVE-2021-26295-POC 利用DNSlog进行CVE-2021-26295的漏洞验证。 使用 poc:将目标放于target.txt后运行python poc.py即可。(Jdk环境需<12,否则ysoserial无法正常生成有效载荷) exp:python exp.py…

dns-analysisexploitationpayload-generation+3
5 years ago
Log4j-check preview

Log4j-check

GitHubbigsizeme/log4j-check

log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload

dns-analysisexploitationpayload-generation+3
704 years ago
Previous123Next