Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
107 results
rpi-hunter preview

rpi-hunter

GitHubbusescanfly/rpi-hunter

Auto discover and exploit LAN raspberry pi's

exploitationinformation-gatheringnetwork-security+2
1082 years ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9842 days ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
39.1k1 day ago
CVE-2024-50986 preview

CVE-2024-50986

GitHubriftsandroses/cve-2024-50986

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

binary-exploitationexploitationpayload-generation+4
1 year ago
CVE-2022-34718-PoC preview

CVE-2022-34718-PoC

GitHubseclabresearchbv/cve-2022-34718-poc

Python-based proof-of-concept exploit for CVE-2022-34718, a remote code execution vulnerability in IPv6 on Windows, using Scapy to craft and send…

exploitationnetwork-securitypayload-generation+3
493 years ago
Reverse_DNS_Shell preview

Reverse_DNS_Shell

GitHubahhh/reverse_dns_shell

A python reverse shell that uses DNS as the c2 channel

command-and-controldns-analysispayload-generation+2
50710 years ago
ZackAttack preview

ZackAttack

GitHuburbanesec/zackattack

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

authenticationexploitationinformation-gathering+6
26314 years ago
PwnSTAR preview

PwnSTAR

GitHubsilverfoxx/pwnstar

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

captcha-bypassdns-analysisexploitation+7
26112 years ago
meterssh preview

meterssh

GitHubtrustedsec/meterssh

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

command-and-controlexploitationpayload-development+4
5309 years ago
outis preview

outis

GitHubsyss-research/outis

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

command-and-controldns-analysispayload-generation+3
1269 years ago
CVE-2025-2304-exploit preview

CVE-2025-2304-exploit

GitHubjeanback1/cve-2025-2304-exploit

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

educationexploitationlabs-practice+5
5 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubk3ystr0k3r/cve-2026-24061

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

authenticationauthentication-authorizationcommand-and-control+8
33 months ago
evilgrade preview

evilgrade

GitHubinfobyte/evilgrade

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

dns-analysisexploit-frameworkspayload-generation+4
1.3k5 years ago
ufonet preview

ufonet

GitHubepsylon/ufonet

UFONet - Denial of Service Toolkit

command-and-controlcryptographyexploitation+6
2.5k13 days ago
dns-black-cat preview

dns-black-cat

GitHubzux0x3a/dns-black-cat

Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

command-and-controldata-exfiltrationdns-analysis+3
1124 years ago
CVE-2024-25641 preview

CVE-2024-25641

GitHubsafarchand/cve-2024-25641

PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26

exploitationpayload-generationpenetration-testing+3
22 years ago
AsyncRAT-C-Sharp preview

AsyncRAT-C-Sharp

GitHubnyan-x-cat/asyncrat-c-sharp

Open-Source Remote Administration Tool For Windows C# (RAT)

command-and-controldata-exfiltrationpassword-cracking+5
3.0k2 years ago
TinkererShell preview
Archived

TinkererShell

GitHub4n4nk3/tinkerershell

A simple python reverse shell written just for fun.

command-and-controldata-exfiltrationdns-analysis+8
623 years ago
Previous123456Next