Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
107 results
poisontap preview

poisontap

GitHubsamyk/poisontap

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

authenticationcommand-and-controldata-exfiltration+7
6.5k
7 years ago
WinPwn preview

WinPwn

GitHubs3cur3th1ssh1t/winpwn

Automation for internal Windows Penetrationtest / AD-Security

exploitationpenetration-testingpenetration-testing-frameworks+4
3.7k11 months ago
stunner preview

stunner

GitHubfirefart/stunner

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

exploitationmisconfigurationnetwork-security+3
8591 day ago
log4j2burpscanner preview

log4j2burpscanner

GitHubf0ng/log4j2burpscanner

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

dns-analysisexploitationpenetration-testing+2
8413 years ago
pentestly preview
Archived

pentestly

GitHubpraetorian-inc/pentestly

Python and Powershell internal penetration testing framework

command-and-controlexploitationinformation-gathering+8
72110 years ago
sonar.js preview

sonar.js

GitHubmandatoryprogrammer/sonar.js

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

exploitationinformation-gatheringpenetration-testing+3
55210 years ago
portia preview
Archived

portia

GitHubspiderlabs/portia

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

exploitationinformation-gatheringlateral-movement+5
5016 years ago
DahuaConsole preview

DahuaConsole

GitHubmcw0/dahuaconsole

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

authentication-authorizationembedded-systems-securityexploitation+5
3181 year ago
DVS preview

DVS

GitHubscorpioneslabs/dvs

D(COM) V(ulnerability) S(canner) AKA Devious swiss army knife - Lateral movement using DCOM Objects

command-and-controlexploitationlateral-movement+3
2565 years ago
SCANNER-INURLBR preview

SCANNER-INURLBR

GitHubmrcl0wnlab/scanner-inurlbr

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

crawlerdns-subdomain-enumerationemail-harvesting+6
2291 year ago
Vulnerability-Disclosures preview

Vulnerability-Disclosures

GitHubmandiant/vulnerability-disclosures

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

exploitationpenetration-testingred-teaming+3
2191 day ago
attack-surface-framework preview

attack-surface-framework

GitHubvmware-labs/attack-surface-framework

Tool to discover external and internal network attack surface

dns-subdomain-enumerationexploitationinformation-gathering+8
2062 years ago
relay_bible preview

relay_bible

GitHubrootsecdev/relay_bible

Technical Reference to multiple relay techniques

authenticationcurated-resourceseducation+8
1933 months ago
publications preview

publications

GitHubelttam/publications

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

binary-exploitationcurated-resourcesexploitation+5
16622 days ago
CVE-2021-28663 preview

CVE-2021-28663

GitHublntrx/cve-2021-28663

A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)

android-securitybinary-exploitationexploitation+2
1284 years ago
IronPE preview

IronPE

GitHubiss4cf0ng/ironpe

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

binary-analysisbinary-exploitationeducation+5
1245 months ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubaydinnyunus/cve-2025-29927

CVE-2025-29927 Proof of Concept

authentication-authorizationeducationexploitation+3
1021 year ago
rebindMultiA preview

rebindMultiA

GitHubrhynorater/rebindmultia

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

dns-analysisexploitationpenetration-testing+2
643 years ago
Previous123456Next