Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
killshot preview

killshot

GitHubbahaabdelwahed/killshot

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

exploit-frameworksfuzzinginformation-gathering+6
787
10 months ago
hackingtool preview

hackingtool

GitHubz4nzu/hackingtool

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

cloud-securityexploitationforensics+9
80.2k1 month ago
r2s preview

r2s

GitHubzamdevio/r2s

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

command-and-controlexploitationinformation-gathering+5
210 months ago
EvilOSX preview

EvilOSX

GitHubmarten4n6/evilosx

An evil RAT (Remote Administration Tool) for macOS / OS X.

command-and-controlinformation-gatheringpassword-cracking+6
2.4k5 years ago
EggShell preview

EggShell

GitHublucasjacks0n/eggshell

iOS/macOS/Linux Remote Administration Tool

command-and-controlexploitationinformation-gathering+7
1.8k8 years ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3048 years ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1287 years ago
bscan preview

bscan

GitHubwelchbj/bscan

an asynchronous target enumeration tool

ctfinformation-gatheringnetwork-mapping+4
2527 years ago
Metadata-Attacker preview

Metadata-Attacker

GitHubrub-nds/metadata-attacker

A tool to generate media files with malicious metadata

information-gatheringpayload-generationpenetration-testing+1
1287 years ago
Vm4J preview

Vm4J

GitHubns-sp4ce/vm4j

A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager

exploitationinformation-gatheringpayload-generation+3
2074 years ago
Vailyn preview

Vailyn

GitHubvainlystrain/vailyn

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

exploitationinformation-gatheringpayload-generation+3
1995 years ago
doctrack preview

doctrack

GitHubwavvs/doctrack

Tool to manipulate and weaponize Office Open XML documents.

information-gatheringpayload-generationphishing-tools+1
723 years ago
Remot3d preview

Remot3d

GitHubmakiraid/remot3d

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

information-gatheringpayload-generationpenetration-testing+3
187 years ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubthemehackers/cve-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

exploitationinformation-gatheringpayload-generation+3
101 year ago
CVE-2020-1938_Ghostcat-PoC preview

CVE-2020-1938_Ghostcat-PoC

GitHubabrewer251/cve-2020-1938_ghostcat-poc

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

exploitationinformation-gatheringpayload-generation+3
9 months ago
toxssin preview

toxssin

GitHubt3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

exploitationinformation-gatheringpayload-generation+4
1.5k1 year ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
64 months ago
CVE-2026-64638-XSS-to-Shell-PoC preview

CVE-2026-64638-XSS-to-Shell-PoC

GitHubeh-amish/cve-2026-64638-xss-to-shell-poc

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

information-gatheringpayload-generationpenetration-testing+3
31 month ago
Previous12Next