Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
999 results
Out-FINcodedCommand preview

Out-FINcodedCommand

GitHubdanielbohannon/out-fincodedcommand

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

command-and-controldefensive-toolseducation+2
108
9 years ago
Autopwn preview

Autopwn

GitHubrpranshu/autopwn

A simple bash based metasploit automation tool!

educationexploit-frameworkspayload-generation+2
1266 years ago
log4j-poc preview

log4j-poc

GitHubcyberxml/log4j-poc

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

educationexploitationlabs-practice+4
723 years ago
SHGenOb preview

SHGenOb

GitHuboldboy21/shgenob

Python based tool for generating Shellcode from PIC C

binary-analysiseducationencryption-decryption-tools+5
439 months ago
Follina preview

Follina

GitHubabdulrkb/follina

Remote Access Shell for Windows (based on cve-2022-30190)

command-and-controleducationexploitation+4
52 years ago
PaperCut-Authentication_Bypass_and_RCE preview

PaperCut-Authentication_Bypass_and_RCE

GitHubjoaoaugustom/papercut-authentication_bypass_and_rce

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

authenticationeducationexploitation+5
2 months ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
RemoteMouse-3.008-RCE preview

RemoteMouse-3.008-RCE

GitHubgoultarde/remotemouse-3.008-rce

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

educationexploitationpayload-generation+3
1 year ago
adbsploit preview
Archived

adbsploit

GitHubmesquidar/adbsploit

A python based tool for exploiting and managing Android devices via ADB

android-securitydata-exfiltrationexploitation+6
9033 years ago
luckystrike preview
Archived

luckystrike

GitHubcuri0usjack/luckystrike

A PowerShell based utility for the creation of malicious Office macro documents.

educationpayload-generationpenetration-testing+2
1.1k8 years ago
ZipExec preview

ZipExec

GitHubtylous/zipexec

A unique technique to execute binaries from a password protected zip

defensive-toolspayload-developmentpayload-generation+2
1.0k4 years ago
DNSStager preview

DNSStager

GitHubmhaskar/dnsstager

Hide your payload in DNS

command-and-controldns-analysisexploitation+3
6223 years ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4404 years ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3058 years ago
MsfMania preview

MsfMania

GitHublepotekil/msfmania

Python AV Evasion Tools

binary-analysiseducationencryption-decryption-tools+9
51510 months ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2344 months ago
BadOutlook preview

BadOutlook

GitHubaahmad097/badoutlook

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

command-and-controlemail-securityexploitation+3
1375 years ago
Previous123…56Next