Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
Phantom-Evasion-Loader preview

Phantom-Evasion-Loader

GitHubjm00nj/phantom-evasion-loader

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

binary-exploitationcommand-and-controleducation+6
113
2 months ago
go-http-proxy-to-socks preview

go-http-proxy-to-socks

GitHubshadowy-pycoder/go-http-proxy-to-socks

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

dns-analysisdns-fuzzingids-ips-evasion+6
708 days ago
deepce preview

deepce

GitHubstealthcopter/deepce

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

container-escapecontainer-securityexploitation+5
1.6k9 months ago
cracken preview

cracken

GitHubshmuelamar/cracken

a fast password wordlist generator, Smartlist creation and password hybrid-mask analysis tool written in pure safe Rust

hash-analysispassword-attackspassword-cracking+1
3784 years ago
grill preview

grill

GitHubunkaktus/grill

global rate-limiting in Linux (CVE-2016-5696) scanner

exploitationnetwork-securitypenetration-testing+2
19 years ago
PythonMemoryModule preview

PythonMemoryModule

GitHubnaksyn/pythonmemorymodule

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

exploit-frameworkspenetration-testingred-teaming
3382 years ago
sandmap preview

sandmap

GitHubtrimstray/sandmap

Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+6
1.9k1 year ago
pypykatz preview

pypykatz

GitHubskelsec/pypykatz

Mimikatz implementation in pure Python

authenticationdigital-forensicsencryption-decryption-tools+4
3.4k5 months ago
nimux preview

nimux

GitHubblue0x1/nimux

Pure-Nim network enumeration and remote execution toolkit for authorized security assessments. Supports SMB, LDAP, Kerberos, WinRM, database clients,…

authenticationcommand-and-controlexploitation+6
91 month ago
JavaPayload preview

JavaPayload

GitHubschierlm/javapayload

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

exploitationmisconfigurationpayload-development+3
1281 year ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubrocket-panda/cve-2025-9074

Bash-based exploit script for CVE-2025-9074 that abuses the internal Docker API to mount the host C drive, execute commands inside a container, and…

cloud-securitycontainer-escapeexploitation+3
6 months ago
rdpy preview

rdpy

GitHubcitronneur/rdpy

Remote Desktop Protocol in Twisted Python

network-securitypenetration-testingred-teaming+1
1.7k6 years ago
http2-security-lab preview

http2-security-lab

GitHubmadhantr0/http2-security-lab

HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python…

defensive-toolseducationlabs-practice+4
3 months ago
InjuredAndroid preview
Archived

InjuredAndroid

GitHubb3nac/injuredandroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

android-securityctfeducation+5
7615 years ago
cmsms-sqli preview

cmsms-sqli

GitHubtim-karov/cmsms-sqli

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

ctfexploitationpassword-cracking+3
8 months ago
CVE-2021-1675 preview

CVE-2021-1675

GitHubcalebstewart/cve-2021-1675

Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)

exploitationpayload-generationpenetration-testing+1
1.1k5 years ago
apache__mina-sshd_CVE-2023-35887_2-9-2 preview

apache__mina-sshd_CVE-2023-35887_2-9-2

GitHubshoucheng3/apache__mina-sshd_cve-2023-35887_2-9-2

Pure Java SSH client/server library implementing SSH-2 protocol with support for multiple ciphers, key exchanges, authentication methods, SFTP, SCP,…

authenticationcryptographyencryption-decryption-tools+5
1 year ago
CVE-2017-9779 preview

CVE-2017-9779

GitHubhomjxi0e/cve-2017-9779

Automatic execution Payload From Windows By Path Users All Exploit Via File bashrc

exploitationpayload-developmentpenetration-testing+3
9 years ago
Previous12Next