Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
ddoor preview

ddoor

GitHubrek7/ddoor

DDoor - cross platform backdoor using dns txt records

anti-botcommand-and-controldns-analysis+5
305 years ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubobscura-cert/cve-2025-33073

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

authenticationcommand-and-controldns-analysis+7
11 year ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5334 years ago
mitm6 preview

mitm6

GitHubdirkjanm/mitm6

Exploits Windows IPv6 default configuration to spoof DNS via DHCPv6, redirecting victim traffic for credential relaying and man-in-the-middle attacks…

authenticationdns-analysisinformation-gathering+3
1.9k4 years ago
Tourmaline preview

Tourmaline

GitHubv-pun215/tourmaline

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

command-and-controlcryptographydigital-forensics+7
1024 days ago
firepwner preview

firepwner

GitHubmattimustang/firepwner

Exploit for CVE-2015-6357 Cisco FireSIGHT Management Center Certificate Validation Vulnerability

command-and-controldns-analysisexploitation+4
610 years ago
ip-finder-cli preview

ip-finder-cli

GitHubipfinder-io/ip-finder-cli

The official command line client for IPFinder

dns-analysisinformation-gatheringnetwork-mapping+1
117 years ago
waybend preview

waybend

GitHubprinciplebreach/waybend

Self-hosted SSRF redirect, payload, callback, and DNS workbench

command-and-controldns-analysisinformation-gathering+9
523 days ago
goldig preview
Archived

goldig

GitLabrtfmkiesel/goldig

Execute commands on Windows via malicious TXT DNS records

command-and-controldns-analysisexploitation+3
3 years ago
godoh preview

godoh

GitHubsensepost/godoh

🕳 godoh - A DNS-over-HTTPS C2

command-and-controldns-analysispayload-development+1
8072 years ago
MyLog4Shell preview

MyLog4Shell

GitHubkal1gh0st/mylog4shell

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

dns-analysisexploitationinformation-gathering+3
14 years ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
1 month ago
explain-my-curl preview

explain-my-curl

GitHubakgitrepos/explain-my-curl

Takes a curl command and explains DNS/TLS/HTTP details step-by-step

dns-analysiseducationgeneral-purpose-utilities+3
987 months ago
procrustes preview

procrustes

GitHubvp777/procrustes

A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering

command-and-controldata-exfiltrationdns-analysis+2
2105 years ago
globalping-probe preview

globalping-probe

GitHubjsdelivr/globalping-probe

The globalping probe code that runs on your hardware and connects to the global community network of probes

cloud-securitydevsecopsdns-analysis+3
21214h 3m ago
rita preview

rita

GitHubactivecm/rita

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

anomaly-detectioncommand-and-controldns-analysis+4
6533 months ago
lockjaw preview

lockjaw

GitHubg13net/lockjaw

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

command-and-controldns-analysisexploit-frameworks+9
266 days ago
CVE-2017-9430 preview

CVE-2017-9430

GitHubhomjxi0e/cve-2017-9430

Proof-of-concept exploit for CVE-2017-9430, a stack-based buffer overflow in dnstracer 1.9, triggered via a long command-line argument causing denial…

binary-exploitationdns-analysisexploitation+2
9 years ago
Previous12345Next