Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
ezXSS preview

ezXSS

GitHubssl/ezxss

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

information-gatheringpayload-generationpenetration-testing+2
2.3k
2 months ago
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k4 months ago
wasmforge preview

wasmforge

GitHubpraetorian-inc/wasmforge

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

binary-analysiscommand-and-controlexploit-frameworks+9
1313 months ago
routersploit preview

routersploit

GitHubthreat9/routersploit

Exploitation Framework for Embedded Devices

bluetooth-securityembedded-systems-securityexploitation+7
13.2k4 months ago
hideNsneak preview

hideNsneak

GitHubrmikehodges/hidensneak

a CLI for ephemeral penetration testing

cloud-securitycommand-and-controlpayload-generation+5
186 years ago
pwncat preview

pwncat

GitHubcytopia/pwncat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

command-and-controlids-ips-evasionlateral-movement+7
2.0k4 years ago
SharpShooter preview

SharpShooter

GitHubmdsecactivebreach/sharpshooter

Payload Generation Framework

command-and-controldns-analysisexploitation+9
2.0k2 years ago
redsnarf preview

redsnarf

GitHubnccgroup/redsnarf

RedSnarf is a pen-testing / red-teaming tool for Windows environments

command-and-controlexploitationhash-analysis+9
1.2k9 years ago
InfraGuard preview

InfraGuard

GitHubwhispergate/infraguard

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

anti-botcommand-and-controldns-analysis+8
3171 month ago
DNSStager preview

DNSStager

GitHubmhaskar/dnsstager

Hide your payload in DNS

command-and-controldns-analysisexploitation+3
6223 years ago
ddoor preview

ddoor

GitHubrek7/ddoor

DDoor - cross platform backdoor using dns txt records

anti-botcommand-and-controldns-analysis+5
304 years ago
nimrm preview

nimrm

GitHubblue0x1/nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

authenticationcommand-and-controlinformation-gathering+6
613 days ago
pystinger preview

pystinger

GitHubfunnywolf/pystinger

Bypass firewall for traffic forwarding using webshell

command-and-controlexploit-frameworksids-ips-evasion+5
1.4k4 years ago
shells preview

shells

GitHub4ndr34z/shells

Script for generating revshells

command-and-controlctfeducation+9
4862 years ago
parquet-canary-exploit-rce-poc-CVE-2025-30065 preview

parquet-canary-exploit-rce-poc-CVE-2025-30065

GitHubf5-labs/parquet-canary-exploit-rce-poc-cve-2025-30065

Generates malicious Apache Parquet files to test for CVE-2025-30065 RCE vulnerability via SSRF callback. Designed for authorized security testing of…

exploitationpayload-generationpenetration-testing+3
121 year ago
SharpSploitConsole preview

SharpSploitConsole

GitHubanthemtotheego/sharpsploitconsole

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

command-and-controlexploitationinformation-gathering+9
1814 years ago
WAREED-DNS-C2 preview

WAREED-DNS-C2

GitHubfaisal-p27/wareed-dns-c2

DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

command-and-controlids-ips-evasionpayload-development+3
1481 year ago
nmap-log4shell preview

nmap-log4shell

GitHubgiterlizzi/nmap-log4shell

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

exploitationnetwork-securitypayload-generation+4
794 years ago
Previous12Next