Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
buttinsky preview

buttinsky

GitHubmushorg/buttinsky

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

information-gatheringintrusion-detectionmalware-analysis+2
82
13 years ago
Reticulum preview

Reticulum

GitHubmarkqvist/reticulum

The cryptography-based networking stack for building unstoppable networks with LoRa, Packet Radio, WiFi and everything in between.

authenticationcryptographyencryption-decryption-tools+4
7.5k3 days ago
CVE-2025-26466 preview

CVE-2025-26466

GitHubrxerium/cve-2025-26466

The OpenSSH client and server are vulnerable to a pre-authentication DoS attack between versions 9.5p1 to 9.9p1 (inclusive) that causes memory and…

exploitationnetwork-securityvulnerability-analysis+1
511 months ago
honssh preview
Archived

honssh

GitHubtnich/honssh

HonSSH is designed to log all SSH communications between a client and server.

information-gatheringlog-analysisnetwork-security+1
3724 years ago
CVE-2025-26465 preview

CVE-2025-26465

GitHubrxerium/cve-2025-26465

MitM attack allowing a malicious interloper to impersonate a legitimate server when a client attempts to connect to it

exploitationnetwork-securitypenetration-testing+3
911 months ago
HPE-Aruba-AOS8-Vulnerabilities preview

HPE-Aruba-AOS8-Vulnerabilities

GitHubjm00nj/hpe-aruba-aos8-vulnerabilities

ArubaOS 8.13.2.0 pre-auth attack surface research. XXE+SSRF, ICMP reflection, buffer over-read, hardcoded credentials — all submitted to HPE…

binary-analysisexploitationfirmware-analysis+3
43 months ago
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
7435 years ago
PortBender preview

PortBender

GitHubpraetorian-inc/portbender

TCP Port Redirection Utility

command-and-controlexploitationlateral-movement+4
7885 years ago
Atlas preview

Atlas

GitHubportbuster1337/atlas

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

exploitationlateral-movementnetwork-security+4
8315 days ago
BadSamba preview

BadSamba

GitHubstrozfriedberg/badsamba

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

exploitationlateral-movementnetwork-security+3
226 years ago
PetitPotam-notest preview

PetitPotam-notest

GitHubcorelight/petitpotam-notest

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

exploitationintrusion-detectionlateral-movement+2
2 years ago
CVE-2020-10749 preview

CVE-2020-10749

GitHubknqyf263/cve-2020-10749

Proof-of-concept exploit for CVE-2020-10749 demonstrating Kubernetes MitM attacks via IPv6 rogue router advertisements between pods.

cloud-securitycontainer-securityexploitation+2
256 years ago
secfesc preview

secfesc

GitHubake13-art/secfesc

Lightweight security state inspector for Linux — bridging the gap between pretty fetch tools and heavy-duty audit frameworks.

authenticationconfiguration-auditingdefensive-tools+3
213 months ago
aimp preview

aimp

GitHubfabriziosalmi/aimp

A serverless networking protocol designed for resilient state synchronization between autonomous agents in fragmented, low-bandwidth networks

cryptographyeducationembedded-systems-security+6
51 day ago
Bastillion preview

Bastillion

GitHubbastillion-io/bastillion

Bastillion gives you a clean, browser-based way to manage SSH access across all your systems—like a bastion host with a friendly dashboard.

authentication-authorizationidentity-access-managementnetwork-security+2
3.6k2 days ago
LTESniffer preview

LTESniffer

GitHubsyssec-kaist/ltesniffer

An Open-source LTE Downlink/Uplink Eavesdropper

educationinformation-gatheringnetwork-security+5
2.2k1 year ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.1k22h 23m ago
jackhammer preview

jackhammer

GitHubolacabs/jackhammer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

code-analysisconfiguration-auditingdevsecops+9
7387 years ago
Previous12Next