Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
679
2 days ago
hayduk preview

hayduk

GitHubjolovicdev/hayduk

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

exploit-frameworksnetwork-mappingpenetration-testing-frameworks+3
69 days ago
CVE-2026-31431 preview

CVE-2026-31431

GitHubstarxsky/cve-2026-31431

Provides attack source code and sniffing tools for CVE-2026-31431, a kernel vulnerability, along with mitigation instructions including disabling the…

exploitationexploit-frameworkspenetration-testing+1
4 months ago
Apache-Dubbo-Hessian2-CVE-2021-43297 preview

Apache-Dubbo-Hessian2-CVE-2021-43297

GitHublongofo/apache-dubbo-hessian2-cve-2021-43297

Demonstrates a proof-of-concept exploit for CVE-2021-43297, a deserialization vulnerability in Apache Dubbo's Hessian2 protocol, with provider and…

binary-exploitationexploitationexploit-frameworks+2
464 years ago
CVE-2007-2447-Exploitation-SIEM-Detection-Lab preview

CVE-2007-2447-Exploitation-SIEM-Detection-Lab

GitHubharshiys/cve-2007-2447-exploitation-siem-detection-lab

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

educationexploitationexploit-frameworks+7
1 month ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k16 days ago
process-inject-kit preview

process-inject-kit

GitHubrasta-mouse/process-inject-kit

Port of Cobalt Strike's Process Inject Kit

adversarial-attackexploit-frameworkspayload-development+2
1931 year ago
CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit preview

CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit

GitHubcerberusmrxi/cve-2023-44487-http2-dos-rapid-reset-exploit

Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control,…

adversarial-attackexploitationexploit-frameworks+4
11 month ago
dapr preview

dapr

GitHubnccgroup/dapr

Driver Attack Platform for Linux

android-securitybinary-exploitationdebuggers+5
196 years ago
better_opts_attacks preview

better_opts_attacks

GitHubnishitvp/better_opts_attacks

Attack framework for breaking fine-tuning based prompt injection defenses (SecAlign, SecAlign++, StruQ) using architecture-aware adversarial attacks…

adversarial-attackai-securityexploit-frameworks+2
116 months ago
CVE-2020-0022 preview

CVE-2020-0022

GitHubthemmokhtar/cve-2020-0022

A fully public exploit of the CVE-2020-0022 BlueFrag Android RCE Vulnerability (tested on Pixel 3 XL)

android-securitybinary-exploitationbluetooth-security+7
222 years ago
linux-root-kit preview

linux-root-kit

GitHubic3-512/linux-root-kit

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

command-and-controldigital-forensicseducation+8
101 year ago
CVE-2025-26466-msf preview

CVE-2025-26466-msf

GitHubmrowkoob/cve-2025-26466-msf

CVE-2025-26466 - SSH Ping DoS Ruby module for Metasploit Framework

educationexploit-frameworksnetwork-security+2
1 year ago
redthread preview

redthread

GitHubmatheusht/redthread

An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision…

adversarial-attackai-securitydefensive-tools+7
505 days ago
awesome-hacking-lists preview

awesome-hacking-lists

GitHubtaielab/awesome-hacking-lists

A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and…

curated-resourceseducationexploit-frameworks+6
1.4k9 months ago
AttackSurfaceManagement preview

AttackSurfaceManagement

GitHub1n3/attacksurfacemanagement

Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam…

exploit-frameworksinformation-gatheringosint+6
1064 years ago
Sn1per preview

Sn1per

GitHub1n3/sn1per

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

devsecopsexploit-frameworksinformation-gathering+7
11.3k2 months ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k3 months ago
Previous123Next