Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k
4 months ago
iptable_evil preview

iptable_evil

GitHubflamingspork/iptable_evil

Kernel-level iptables backdoor that accepts all packets with the RFC 3514 evil bit set, bypassing firewall rules. Includes in-tree and out-of-tree…

educationexploitationids-ips-evasion+2
555 years ago
lutlol preview

lutlol

GitHubmagisterquis/lutlol

Living Under the Land on Linux ~ Bsides Belfast/Vienna 2025

command-and-controleducationids-ips-evasion+3
3810 months ago
LID preview

LID

GitHubazqzazq1/lid

LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux…

binary-analysiseducationexploitation+6
204 months ago
tetragon-dirtyfrag preview

tetragon-dirtyfrag

GitHubarmircetaj/tetragon-dirtyfrag

Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy

binary-exploitationdefensive-toolseducation+5
12 months ago
MasterHttpRelayVPN preview

MasterHttpRelayVPN

GitHubmasterking32/masterhttprelayvpn

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

dns-analysiseducationencryption-decryption-tools+4
3.9k3 months ago
Bashfuscator preview

Bashfuscator

GitHubbashfuscator/bashfuscator

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

defensive-toolseducationids-ips-evasion+3
2.0k6 years ago
ageverificationbypass preview

ageverificationbypass

GitHubhaplessidiot/ageverificationbypass

Bypass age verification service from redhat

defensive-toolseducationids-ips-evasion+3
955 months ago
Nac_Bypass_Agent preview

Nac_Bypass_Agent

GitHubalperenugurlu/nac_bypass_agent

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

educationids-ips-evasionimpersonation-tools+5
733 years ago
macos_app_structure preview

macos_app_structure

GitHubyo-yo-yo-jbo/macos_app_structure

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

educationids-ips-evasionpayload-development+2
472 months ago
Umbra preview

Umbra

GitHubh3xduck/umbra

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

command-and-controleducationencryption-decryption-tools+6
1375 years ago
CyberDefense-Lab preview

CyberDefense-Lab

GitHubumidguluzada/cyberdefense-lab

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.

educationids-ips-evasionintrusion-detection+5
61 month ago
CVE-2025-47827 preview

CVE-2025-47827

GitHubzedeldi/cve-2025-47827

PoC and vulnerability report for CVE-2025-47827.

binary-exploitationeducationexploitation+8
410 months ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
2 months ago
wazuh-home-soc preview

wazuh-home-soc

GitHuborevic21/wazuh-home-soc

Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS…

educationexploitationids-ips-evasion+6
2 months ago
CVE-2024-27198-SOC-Lab preview

CVE-2024-27198-SOC-Lab

GitHubptd200110/cve-2024-27198-soc-lab

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

educationexploitationids-ips-evasion+7
23 months ago
CVE-2022-30190-Follina-Lab preview

CVE-2022-30190-Follina-Lab

GitHubu1tr0nex/cve-2022-30190-follina-lab

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

command-and-controleducationexploitation+7
4 months ago
network-security-snort preview

network-security-snort

GitHubtaisa456/network-security-snort

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

defensive-toolseducationexploitation+6
4 months ago
Previous12345Next