Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
cloudfox preview

cloudfox

GitHubbishopfox/cloudfox

Automating situational awareness for cloud penetration tests.

cloud-infrastructure-securitycloud-securityexploitation+7
2.6k
20 days ago
CVE-2024-11318 preview

CVE-2024-11318

GitHubxthalach/cve-2024-11318

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

authentication-authorizationexploitationinformation-gathering+3
11 year ago
attack-surface-framework preview

attack-surface-framework

GitHubvmware-labs/attack-surface-framework

Tool to discover external and internal network attack surface

dns-subdomain-enumerationexploitationinformation-gathering+8
2062 years ago
NtlmRelayToEWS preview

NtlmRelayToEWS

GitHubarno0x/ntlmrelaytoews

ntlm relay attack to Exchange Web Services

email-securityexploitationinformation-gathering+4
3328 years ago
RelayKing-Depth preview

RelayKing-Depth

GitHubdepthsecurity/relayking-depth

Dominate the domain. Relay to royalty.

exploitationids-ips-evasioninformation-gathering+7
3565 months ago
CVE-2021-26855-exploit-Exchange preview

CVE-2021-26855-exploit-Exchange

GitHubhaotiku/cve-2021-26855-exploit-exchange

Automated scanner and exploit tool for CVE-2021-26855 targeting Microsoft Exchange servers, enabling remote code execution on vulnerable instances…

exploitationpenetration-testingreconnaissance+2
5 years ago
Dosinator preview

Dosinator

GitHubhalildeniz/dosinator

DoSinator is a powerful Denial of Service (DoS) testing tool developed in Python.

exploitationinformation-gatheringnetwork-security+3
1432 years ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
2361 month ago
CVE-2023-27350-POC preview

CVE-2023-27350-POC

GitHubimancybersecurity/cve-2023-27350-poc

Proof-of-concept exploit for CVE-2023-27350 targeting authentication bypass in PaperCut MF/NG print management software. Includes Shodan dorks for…

authenticationexploitationreconnaissance+2
121 year ago
CVE-2022-26809 preview

CVE-2022-26809

GitHubwebsecnl/cve-2022-26809

Remote Code Execution Exploit in the RPC Library

binary-exploitationexploitationpenetration-testing+2
284 years ago
CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC preview

CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC

GitHubabrewer251/cve-2024-38475_sonicboom_apache_url_traversal_poc

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

exploitationfuzzingpenetration-testing+3
1 year ago
gato preview
Archived

gato

GitHubpraetorian-inc/gato

GitHub Actions Pipeline Enumeration and Attack Tool

devsecopsexploitationinformation-gathering+7
94 months ago
esp32-wifi-penetration-tool preview

esp32-wifi-penetration-tool

GitHubrisinek/esp32-wifi-penetration-tool

Exploring possibilities of ESP32 platform to attack on nearby Wi-Fi networks.

educationexploitationhardware-hacking+6
3.1k3 years ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3058 years ago
Pesidious preview

Pesidious

GitHubcyberforce/pesidious

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

adversarial-attackai-securityexploitation+3
1745 years ago
rebindMultiA preview

rebindMultiA

GitHubrhynorater/rebindmultia

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

dns-analysisexploitationpenetration-testing+2
643 years ago
DNSSpoof preview

DNSSpoof

GitHubdtrecherel/dnsspoof

A DNS spoofer tool written in Python3.

adversarial-attackexploitationimpersonation-tools+3
69 years ago
CVE-2026-21010-VoIP-SIP-Digest-Authentication-Replay preview

CVE-2026-21010-VoIP-SIP-Digest-Authentication-Replay

GitHubgeorge0papasotiriou/cve-2026-21010-voip-sip-digest-authentication-replay

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

adversarial-attackauthentication-authorizationexploitation+3
1 month ago
Previous12345Next