Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
126 results
Bella preview

Bella

GitHub00xglitch/bella

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

command-and-controldata-exfiltrationids-ips-evasion+8
205
3 years ago
cromos preview

cromos

GitHubjimywork/cromos

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

command-and-controldata-exfiltrationlateral-movement+5
1248 years ago
TokenMan preview

TokenMan

GitHubsecureworks/tokenman

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

authenticationcloud-securityinformation-gathering+2
1033 years ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
10119 days ago
teletunnel preview

teletunnel

GitHubmhdgning131/teletunnel

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

command-and-controldata-exfiltrationids-ips-evasion+7
445 months ago
Find-AdminAccess preview

Find-AdminAccess

GitHublsecqt/find-adminaccess

This C# tool sprays for admin access over the entire domain

information-gatheringlateral-movementnetwork-mapping+4
908 months ago
ica2tcp preview

ica2tcp

GitHubsynacktiv/ica2tcp

A SOCKS proxy for Citrix.

lateral-movementpenetration-testingpost-exploitation+3
1013 years ago
PrintSpoofer-ReflectiveDLL preview

PrintSpoofer-ReflectiveDLL

GitHubjonyfilc/printspoofer-reflectivedll

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

exploitationlateral-movementpayload-development+4
213 days ago
TokenPlayer preview

TokenPlayer

GitHubs1ckb0y1337/tokenplayer

Manipulating and Abusing Windows Access Tokens.

impersonation-toolslateral-movementpenetration-testing+2
3005 years ago
Dragnmove preview

Dragnmove

GitHuboccamsxor/dragnmove

Infect Shared Files In Memory for Lateral Movement

lateral-movementpost-exploitationred-teaming
1923 years ago
SocksOverRDP preview

SocksOverRDP

GitHubnccgroup/socksoverrdp

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

ids-ips-evasionlateral-movementpenetration-testing+3
1.3k3 years ago
macro_pack preview
Archived

macro_pack

GitHubsevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exploit-frameworkslateral-movementpayload-generation+6
2.3k2 years ago
C3 preview

C3

GitHubreverseclabs/c3

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

command-and-controlexploit-frameworksids-ips-evasion+6
1.8k7 months ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
SCShell preview

SCShell

GitHubmr-un1k0d3r/scshell

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

exploitationlateral-movementpenetration-testing+2
1.7k3 years ago
venom preview

venom

GitHubboku7/venom

Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence

command-and-controlencryption-decryption-toolslateral-movement+6
4369 months ago
RAT-via-Telegram preview

RAT-via-Telegram

GitHubdviros/rat-via-telegram

Windows Remote Post Breach Tool via Telegram

command-and-controldata-exfiltrationinformation-gathering+7
1358 years ago
Invoke-RunAsWithCert preview

Invoke-RunAsWithCert

GitHubsynacktiv/invoke-runaswithcert

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

authenticationlateral-movementpenetration-testing+2
1792 years ago
Previous1234567Next