Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1046 results
CVE-2022-30190-Follina-Lab preview

CVE-2022-30190-Follina-Lab

GitHubu1tr0nex/cve-2022-30190-follina-lab

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

command-and-controleducationexploitation+7
4 months ago
meterpeter preview

meterpeter

GitHubr00t-3xp10it/meterpeter

C2 Powershell Command & Control Framework with BuiltIn Commands

command-and-controlids-ips-evasionpayload-generation+4
5072 years ago
webhandler preview

webhandler

GitHublnxg33k/webhandler

Bash simulator to control a server using PHP system functions.

command-and-controlids-ips-evasionpayload-generation+3
1005 years ago
Chimera preview

Chimera

GitHubtokyoneon/chimera

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

ids-ips-evasionpayload-developmentpayload-generation+2
1.6k6 years ago
pwncat preview

pwncat

GitHubcytopia/pwncat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

command-and-controlids-ips-evasionlateral-movement+7
2.0k4 years ago
DAws preview

DAws

GitHubdotcppfile/daws

Advanced Web Shell

ids-ips-evasionpayload-generationpenetration-testing+6
5809 years ago
peCloakCapstone preview

peCloakCapstone

GitHubv-p-b/pecloakcapstone

Platform independent peCloak fork based on Capstone

binary-analysisids-ips-evasionmalware-analysis+2
10911 years ago
IronSharpPack preview

IronSharpPack

GitHubbc-security/ironsharppack

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

ids-ips-evasionpayload-developmentpayload-generation+2
1212 years ago
Webapp_Pentast preview

Webapp_Pentast

GitHubamhar-hckr/webapp_pentast

CVE-2022-31147 is a path traversal flaw in matthiasmullie/minify. This guide helps security teams test for arbitrary file read on Linux and Windows…

educationexploitationpayload-generation+3
1 year ago
WSL_Payload_Builder preview

WSL_Payload_Builder

GitHubm1ddl3w4r3/wsl_payload_builder

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

payload-developmentpayload-generationpenetration-testing+1
7210 months ago
CVE-2023-45866_WIP preview

CVE-2023-45866_WIP

GitHubv3ilsm1th/cve-2023-45866_wip

Simulates a Bluetooth keyboard to exploit CVE-2023-45866, injecting keystrokes via DuckyScript on vulnerable Android, iOS, macOS, and Linux devices…

bluetooth-securityexploitationhardware-iot-security+4
1 year ago
KLAIOS preview

KLAIOS

GitHublglznl/klaios

KLAIOS is a hybrid security environment that merges Kali Linux’s offensive toolkit with hardened, VPN-bunker-style isolation—enhanced by modern AI…

ai-securitycontainer-securityexploit-frameworks+7
18 months ago
CVE-2022-44149 preview

CVE-2022-44149

GitHubgeniuszly/cve-2022-44149

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

exploitationpayload-generationpenetration-testing+3
52 years ago
cve-2022-42889-text4shell-docker preview

cve-2022-42889-text4shell-docker

GitHubkarthikuj/cve-2022-42889-text4shell-docker

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

container-securityeducationexploitation+3
763 years ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
2 months ago
hackingtool preview

hackingtool

GitHubz4nzu/hackingtool

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

cloud-securityexploitationforensics+9
79.8k1 month ago
harpyTools preview

harpyTools

GitHubjssngc/harpytools

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

command-and-controlexploitationlateral-movement+6
2027 days ago
CVE-2025-55182-Waf preview

CVE-2025-55182-Waf

GitHubl0n3m4n/cve-2025-55182-waf

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

command-and-controlexploitationpayload-generation+5
29 months ago
Previous12…59Next