Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
56 results
Py-RDP-Patcher preview

Py-RDP-Patcher

GitHubsp00kyskelet0n/py-rdp-patcher

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

lateral-movementpenetration-testingremote-access-tool
65 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5444 years ago
evilrdp preview

evilrdp

GitHubskelsec/evilrdp

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

command-and-controllateral-movementpenetration-testing+3
3101 year ago
BetterRAT preview

BetterRAT

GitHubmwsrc/betterrat

Better Remote Access Trojan

command-and-controldata-exfiltrationlateral-movement+5
559 years ago
CVE-2025-50154 preview

CVE-2025-50154

GitHubrubenformation/cve-2025-50154

POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a…

educationexploitationlateral-movement+1
5611 months ago
GTFOBLookup preview

GTFOBLookup

GitHubnccgroup/gtfoblookup

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

information-gatheringlateral-movementpenetration-testing+3
2913 years ago
File-Tunnel preview

File-Tunnel

GitHubfiddyschmitt/file-tunnel

Tunnel TCP connections through a file

ids-ips-evasionlateral-movementnetwork-mapping+3
1.1k9 days ago
RDPHijack-BOF preview

RDPHijack-BOF

GitHubnetero1010/rdphijack-bof

Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.

exploit-frameworkslateral-movementpenetration-testing+2
3174 years ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
9 months ago
OffensiveNim preview

OffensiveNim

GitHubbyt3bl33d3r/offensivenim

My experiments in weaponizing Nim (https://nim-lang.org/)

binary-exploitationcode-analysiscommand-and-control+8
3.1k2 years ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubkagancapar/cve-2022-29072

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

binary-exploitationcommand-and-controlexploitation+5
6724 years ago
BetterAndroRAT preview

BetterAndroRAT

GitHubmwsrc/betterandrorat

Android Remote Access Trojan

android-securitycommand-and-controldata-exfiltration+8
5459 years ago
SigFlip preview

SigFlip

GitHubmed0x2e/sigflip

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

binary-analysiscode-analysisdefensive-tools+5
1.3k3 years ago
CVE-2025-27591-Meta-below-LPE preview

CVE-2025-27591-Meta-below-LPE

GitHubrippsec/cve-2025-27591-meta-below-lpe

CVE-2025-27591 – Meta below symlink following local privilege escalation (HackTheBox CTF)

binary-exploitationctfexploitation+3
5 months ago
lnkbomb preview
Archived

lnkbomb

GitHubdievus/lnkbomb

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

exploitationinformation-gatheringlateral-movement+3
3631 year ago
PowerSploit preview
Archived

PowerSploit

GitHubpowershellmafia/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

lateral-movementpayload-generationpenetration-testing+5
13.1k6 years ago
maalik preview
Archived

maalik

GitHubquantumcore/maalik

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

command-and-controlexploitationlateral-movement+6
935 years ago
FUXAPWN preview

FUXAPWN

GitHubhann1bl3l3ct3r/fuxapwn

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

exploitationinformation-gatheringlateral-movement+8
13 months ago
Previous1234Next