Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
terraform-aws-security-group preview

terraform-aws-security-group

GitLabfer1035_terraform/modules/terraform-aws-security-group

Terraform module to manage AWS Security Groups. Currently, the ingress and egress rules support IPv4, IPv6, and Security Group ID inputs.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
2 months ago
Windows-CVE-2024-38063 preview

Windows-CVE-2024-38063

GitHubfredagsguf/windows-cve-2024-38063

Exploit for CVE-2024-38063, a critical RCE in Windows TCP/IP stack via crafted IPv6 packets, enabling arbitrary code execution and system compromise.

exploitationnetwork-securitypenetration-testing+2
1 year ago
SessionView preview

SessionView

GitHublsecqt/sessionview

A portable C# utility for enumerating local and remote windows sessions

digital-forensicsforensicsincident-response+3
568 months ago
no-gdid preview

no-gdid

GitHubkorben00/no-gdid

Read, understand and silence the Windows GDID device identifier (the ID that tracked a hacker through a VPN). Verified on a real Win11 VM. Honest: it…

configuration-auditingdefensive-toolsdigital-forensics+2
2981 month ago
CVE-2025-22870 preview

CVE-2025-22870

GitHubjoshuaprovoste/cve-2025-22870

Proof-of-concept for CVE-2025-22870 demonstrating HTTP proxy bypass in vulnerable versions (<0.36.0) of golang.org/x/net/http/httpproxy. Exploits…

exploitationnetwork-securityvulnerability-analysis+1
21 year ago
CVE-2025-49844-Vulnerability-Scanner preview

CVE-2025-49844-Vulnerability-Scanner

GitHubimbas007/cve-2025-49844-vulnerability-scanner

Scans Redis instances for CVE-2025-49844 (RediShell) critical RCE vulnerability, detecting vulnerable versions and Lua scripting status with…

exploitationnetwork-securitypenetration-testing+3
111 months ago
dmz-security-monitoring-hardening preview

dmz-security-monitoring-hardening

GitHubfreeguy-6/dmz-security-monitoring-hardening

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

configuration-auditingdefensive-toolseducation+5
11 month ago
community-id-spec preview

community-id-spec

GitHubcorelight/community-id-spec

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

digital-forensicsincident-responseintrusion-detection+4
1971 year ago
Zeek-Endpoint-Enrichment preview

Zeek-Endpoint-Enrichment

GitHubcorelight/zeek-endpoint-enrichment

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

information-gatheringlog-analysisnetwork-security+1
42 months ago
cve-2026-0300-audit preview

cve-2026-0300-audit

GitHubtailwindrg/cve-2026-0300-audit

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

cloud-infrastructure-securityconfiguration-auditingdevsecops+3
4 months ago
pritunl preview

pritunl

GitHubpritunl/pritunl

Provides distributed enterprise VPN connectivity using OpenVPN, with centralized management, authentication, and encrypted tunnels for cloud and…

authenticationnetwork-access-controlnetwork-security+2
5.0k10 days ago
firehol preview

firehol

GitHubfirehol/firehol

iptables-based stateful firewall with human-friendly configuration and optional QoS (FireQOS) for bandwidth management.

defensive-toolsnetwork-access-controlnetwork-security
1.6k5 months ago
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
7445 years ago
Invoke-SocksProxy preview

Invoke-SocksProxy

GitHubp3nt4/invoke-socksproxy

Socks proxy, and reverse socks server using powershell.

command-and-controllateral-movementnetwork-security+2
8119 months ago
qubes-mirage-firewall preview

qubes-mirage-firewall

GitHubmirage/qubes-mirage-firewall

Minimal unikernel firewall for QubesOS that filters network traffic, implements NAT, and communicates via Qubes DB and qrexec.

defensive-toolsnetwork-access-controlnetwork-security+1
2381 month ago
SharpSCCM preview

SharpSCCM

GitHubmayyhem/sharpsccm

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

authenticationlateral-movementnetwork-security+3
7035 months ago
SockTail preview

SockTail

GitHubyeeb1/socktail

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

command-and-controllateral-movementnetwork-security+4
57111 months ago
nacker preview

nacker

GitHubcarmaa/nacker

Nacker is a tool to circumvent 802.1x Network Access Control (NAC) on a wired LAN. Nacker will help you locate any non-802.1x configurable hosts on…

network-access-controlnetwork-securitypenetration-testing+2
10512 years ago
Previous123Next