Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
rosemary preview

rosemary

GitHubblue0x1/rosemary

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

command-and-controldns-analysislateral-movement+4
142 months ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubbardlaudian/cve-2025-24071

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

exploitationinformation-gatheringlateral-movement+5
13 days ago
Nerv0usR4bbit preview

Nerv0usR4bbit

GitHub34zy/nerv0usr4bbit

Nerv0us r4bbit - Post Exploitation Windows Enumeration Tool

information-gatheringlateral-movementpenetration-testing+3
43 years ago
CLSIDFinder preview

CLSIDFinder

GitHub0xqn/clsidfinder

PowerShell enumeration script for discovering service-backed COM objects via CLSID/AppID correlation and activation testing.

information-gatheringlateral-movementpenetration-testing+3
37 months ago
cupntlm-Automated-Exploit-For-CVE-2025-33073- preview

cupntlm-Automated-Exploit-For-CVE-2025-33073-

GitHubegcupcake/cupntlm-automated-exploit-for-cve-2025-33073-

cupntlm

authenticationcommand-and-controldns-analysis+9
36 months ago
FUXAPWN preview

FUXAPWN

GitHubhann1bl3l3ct3r/fuxapwn

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

exploitationinformation-gatheringlateral-movement+8
24 months ago
CVE-2025-24071_PoCExtra preview

CVE-2025-24071_PoCExtra

GitHubctabango/cve-2025-24071_pocextra

Proof-of-concept exploit for CVE-2025-24071 that creates a .searchconnector-ms file to trigger SMB authentication when copied, enabling credential…

exploitationinformation-gatheringlateral-movement+3
21 year ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubobscura-cert/cve-2025-33073

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

authenticationcommand-and-controldns-analysis+7
11 year ago
lockjaw preview

lockjaw

GitHubg13net/lockjaw

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

command-and-controldns-analysisexploit-frameworks+9
268 days ago
honeybits preview
Archived

honeybits

GitHub0x4d31/honeybits

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

information-gatheringlateral-movementosint-social-engineering+5
2787 years ago
portia preview
Archived

portia

GitHubspiderlabs/portia

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

exploitationinformation-gatheringlateral-movement+5
5016 years ago
SSH-Snake preview
Archived

SSH-Snake

GitHubmegamansec/ssh-snake

SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.

information-gatheringlateral-movementnetwork-mapping+5
2.3k6 months ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5334 years ago
lnkbomb preview
Archived

lnkbomb

GitHubdievus/lnkbomb

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

exploitationinformation-gatheringlateral-movement+3
3621 year ago
Previous1234Next