Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
windows_tcpip_fuzz preview

windows_tcpip_fuzz

GitHubpersonnumber3377/windows_tcpip_fuzz

This is my attempt at fuzzing the tcpip.sys driver in windows via using scapy. This is inspired by this vulnerability here:…

binary-analysisexploitationfuzzing+2
1 year ago
ecapture preview

ecapture

GitHubgojue/ecapture

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

android-securitydatabase-securitydynamic-analysis-sandboxing+3
15.5k8 days ago
SUNBURST preview

SUNBURST

GitHubmalwaremorghulis/sunburst

Detection for SUNBURST C2 Stage-1 using Shannon Entropy

anomaly-detectioncommand-and-controldns-analysis+3
33 years ago
SilentButDeadly preview

SilentButDeadly

GitHubloosehose/silentbutdeadly

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

command-and-controldefensive-toolsexploitation+7
45310 months ago
CVE-2022-34718-PoC preview

CVE-2022-34718-PoC

GitHubseclabresearchbv/cve-2022-34718-poc

Python-based proof-of-concept exploit for CVE-2022-34718, a remote code execution vulnerability in IPv6 on Windows, using Scapy to craft and send…

exploitationnetwork-securitypayload-generation+3
493 years ago
CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation preview

CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation

GitHubtdevworks/cve-2020-1472-zerologon-demo-detection-mitigation

Educational demo of CVE-2020-1472 (ZeroLogon) detection using Windows Event Logs and Suricata IDS, plus mitigation via Windows Updates. Includes…

educationids-ips-evasionintrusion-detection+3
1 year ago
Posh-SSH preview

Posh-SSH

GitHubdarkoperator/posh-ssh

PowerShell Module for automating tasks on remote systems using SSH

network-securityscripting-automationutilities-frameworks
1.1k6 days ago
Harden-Windows-Security preview

Harden-Windows-Security

GitHubhotcakex/harden-windows-security

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

configuration-auditingdefensive-toolsencryption-decryption-tools+3
4.7k0 days ago
PyStat preview

PyStat

GitHubroothaxor/pystat

Advanced Netstat Using Python For Windows

information-gatheringnetwork-securityutilities-frameworks
459 years ago
Win-PortFwd preview

Win-PortFwd

GitHubdeepzec/win-portfwd

Powershell script to setup windows port forwarding using native netsh client

network-securitypenetration-testingred-teaming
1248 years ago
SMB-Protocol-Vulnerability_CVE-2017-0144 preview

SMB-Protocol-Vulnerability_CVE-2017-0144

GitHubluckyman2907/smb-protocol-vulnerability_cve-2017-0144

Step-by-step lab guide demonstrating the EternalBlue exploit (CVE-2017-0144) against Windows 7 SMB protocol using Metasploit, including setup,…

educationexploitationlabs-practice+3
1 year ago
CVE-2019-0708-scan preview

CVE-2019-0708-scan

GitHublisinan988/cve-2019-0708-scan

Batch scanner for CVE-2019-0708 (BlueKeep) RDP vulnerability with Windows and Linux support, using rdpscan and custom Cscan for mass IP range…

exploitationinformation-gatheringnetwork-security+3
4 years ago
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
7445 years ago
CVE-2026-33829 preview

CVE-2026-33829

GitHubseguridadentrerios/cve-2026-33829

Automated Bash script to passively audit Windows assets for CVE-2026-33829 search: protocol handler vulnerability using tcpdump and SMB connection…

exploitationnetwork-securitypenetration-testing+2
3 months ago
CVE-2024-38063-Remediation preview

CVE-2024-38063-Remediation

GitHubdweger-scripts/cve-2024-38063-remediation

PowerShell audit script to detect missing patches for CVE-2024-38063, an IPv6 vulnerability in Windows systems, enabling rapid remediation…

configuration-auditingnetwork-securityscripting-automation+2
2 years ago
wannafind preview

wannafind

GitHubvalarauco/wannafind

Simple script using nmap to detect CVE-2017-0143 MS17-010 in your network

exploitationinformation-gatheringnetwork-security+3
39 years ago
CVE-2020-1350-Fix preview

CVE-2020-1350-Fix

GitHubsimeononsecurity/cve-2020-1350-fix

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

configuration-auditingdns-analysisincident-response+3
26 years ago
EphemeralNet preview

EphemeralNet

GitHubshardianlabs/ephemeralnet

A secure, decentralized P2P ephemeral network in C++. Features a custom DHT, encrypted transport, and autonomous NAT traversal using high-performance…

cryptographyencryption-decryption-toolsnetwork-security+2
210 months ago
Previous12Next