Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
114 results
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
305
8 years ago
Metadata-Attacker preview

Metadata-Attacker

GitHubrub-nds/metadata-attacker

A tool to generate media files with malicious metadata

information-gatheringpayload-generationpenetration-testing+1
1287 years ago
doctrack preview

doctrack

GitHubwavvs/doctrack

Tool to manipulate and weaponize Office Open XML documents.

information-gatheringpayload-generationphishing-tools+1
723 years ago
CVE-2025-9209 preview

CVE-2025-9209

GitHubnxploited/cve-2025-9209

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

authentication-authorizationexploitationinformation-gathering+5
9 months ago
wordreaper preview

wordreaper

GitHubnemorous/wordreaper

📜 Scrape targeted wordlists for password cracking using CSS selectors

crawlerctfinformation-gathering+5
514 months ago
backcookie preview

backcookie

GitHubjofpin/backcookie

Small backdoor using cookie.

command-and-controlpayload-generationpenetration-testing+3
649 years ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubthemehackers/cve-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

exploitationinformation-gatheringpayload-generation+3
101 year ago
Remot3d preview

Remot3d

GitHubmakiraid/remot3d

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

information-gatheringpayload-generationpenetration-testing+3
177 years ago
hackingtool preview

hackingtool

GitHubz4nzu/hackingtool

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

cloud-securityexploitationforensics+9
79.0k25 days ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1286 years ago
SharpSploitConsole preview

SharpSploitConsole

GitHubanthemtotheego/sharpsploitconsole
command-and-controlexploitationinformation-gathering+9
1824 years ago
r2s preview

r2s

GitHubzamdevio/r2s

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

command-and-controlexploitationinformation-gathering+5
28 months ago
EggShell preview

EggShell

GitHublucasjacks0n/eggshell

iOS/macOS/Linux Remote Administration Tool

command-and-controlexploitationinformation-gathering+7
1.8k7 years ago
Vm4J preview

Vm4J

GitHubns-sp4ce/vm4j

A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager

exploitationinformation-gatheringpayload-generation+3
2094 years ago
Vailyn preview

Vailyn

GitHubvainlystrain/vailyn

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

exploitationinformation-gatheringpayload-generation+3
2004 years ago
CVE-2020-1938_Ghostcat-PoC preview

CVE-2020-1938_Ghostcat-PoC

GitHubabrewer251/cve-2020-1938_ghostcat-poc

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

exploitationinformation-gatheringpayload-generation+3
8 months ago
toxssin preview

toxssin

GitHubt3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

exploitationinformation-gatheringpayload-generation+4
1.4k1 year ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
63 months ago
Previous1234567Next