Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
ibombshell preview

ibombshell

GitHubtelefonica/ibombshell

Tool to deploy a post-exploitation prompt at any time

command-and-controlids-ips-evasionpayload-generation+5
321
5 years ago
CVE-2019-17240 preview

CVE-2019-17240

GitHubpingport80/cve-2019-17240

This is the exploit of CVE-2019-17240.

authenticationexploitationids-ips-evasion+2
35 years ago
CVE-2025-10041 preview

CVE-2025-10041

GitHubnxploited/cve-2025-10041

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

exploitationids-ips-evasionpayload-generation+3
310 months ago
Nodejs-Tracer preview

Nodejs-Tracer

GitHubcheckpointsw/nodejs-tracer

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

anti-botdynamic-analysis-sandboxingids-ips-evasion+3
828 months ago
CVE-2019-9673 preview

CVE-2019-9673

GitHubmgrube/cve-2019-9673

Writeup

exploitationids-ips-evasionphishing+3
47 years ago
duckhunt preview

duckhunt

GitHubpmsosa/duckhunt

:dart: Prevent RubberDucky (or other keystroke injection) attacks

defensive-toolshardware-securityids-ips-evasion
5406 years ago
recomposer preview

recomposer

GitHubsecretsquirrel/recomposer

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

anti-botbinary-analysisids-ips-evasion+2
13312 years ago
nowafpls preview

nowafpls

GitHubassetnote/nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

ids-ips-evasionpenetration-testingred-teaming+3
1.5k1 year ago
Dr0p1t-Framework preview
Archived

Dr0p1t-Framework

GitHubd4vinci/dr0p1t-framework

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

anti-botcommand-and-controlexploitation+9
1.5k7 years ago
PwnSTAR preview

PwnSTAR

GitHubsilverfoxx/pwnstar

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

captcha-bypassdns-analysisexploitation+7
2608 years ago
Detections-CVE-2026-23918 preview
Archived

Detections-CVE-2026-23918

GitHubinsomnisec/detections-cve-2026-23918

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

exploitationids-ips-evasionincident-response+6
3 months ago
AMSI-patches-learned-till-now preview

AMSI-patches-learned-till-now

GitHubreveng007/amsi-patches-learned-till-now

I have documented all of the AMSI patches that I learned till now

curated-resourceseducationids-ips-evasion+3
729 months ago
IronSharpPack preview

IronSharpPack

GitHubbc-security/ironsharppack

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

ids-ips-evasionpayload-developmentpayload-generation+2
1212 years ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
3.9k2 months ago
pstf2 preview

pstf2

GitHubg4lb1t/pstf2

Passive Security Tools Fingerprinting Framework

educationfingerprint-spoofingids-ips-evasion+3
745 years ago