Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2004 results
redsails preview

redsails

GitHubbeetlechunks/redsails

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

ids-ips-evasionpenetration-testingpersistence-mechanisms+2
306
8 years ago
FalconHound preview

FalconHound

GitHubfalconforceteam/falconhound

Automated BloodHound graph updater for blue teams. Enriches AD attack paths with real-time session, group, and CVE data from SIEMs, enabling…

penetration-testingthreat-intelligence
8275 months ago
dorothy preview

dorothy

GitHubelastic/dorothy

Simulates attacker actions in Okta environments to test monitoring and detection capabilities, with modules mapped to MITRE ATT&CK tactics for red…

defensive-toolseducationidentity-access-management+2
1971 year ago
BackDoorSim preview

BackDoorSim

GitHubhalildeniz/backdoorsim

Educational remote administration tool for learning RAT concepts, featuring file transfer, screenshot capture, system monitoring, and webcam access…

educationpenetration-testingpost-exploitation+2
1252 years ago
MacMaster preview

MacMaster

GitHubhalildeniz/macmaster

Advanced Network Interface Management and Monitoring

information-gatheringnetwork-securitypacket-sniffing-analysis+2
352 years ago
CyberDefense-Lab preview

CyberDefense-Lab

GitHubumidguluzada/cyberdefense-lab

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.

educationids-ips-evasionintrusion-detection+5
61 month ago
cve-2024-36401-security-simulator preview

cve-2024-36401-security-simulator

GitHubraniaemran/cve-2024-36401-security-simulator

Educational Python simulator modeling a fictional security incident inspired by CVE-2024-36401 to demonstrate vulnerability management, segmentation,…

defensive-toolseducationincident-response+5
10 days ago
CVE-2026-3288-lab preview

CVE-2026-3288-lab

GitHubbvabhishek/cve-2026-3288-lab

Docker-based vulnerable lab for CVE-2026-3288 NGINX Ingress configuration injection, with exploit scripts, detection monitoring, and remediation…

cloud-infrastructure-securityconfiguration-auditingcontainer-security+6
15 months ago
CVE_2023_44487-Rapid_Reset preview

CVE_2023_44487-Rapid_Reset

GitHubgmh5225/cve_2023_44487-rapid_reset

Python-based testing tool for CVE-2023-44487 (HTTP/2 Rapid Reset) with multiple attack patterns, granular configuration, and monitoring for…

exploitationnetwork-securitypenetration-testing+2
1 year ago
Azure-Networking-Privilege-Escalation-Exploit-CVE-2025-54914 preview

Azure-Networking-Privilege-Escalation-Exploit-CVE-2025-54914

GitHubmrk336/azure-networking-privilege-escalation-exploit-cve-2025-54914

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

cloud-infrastructure-securitycloud-securityeducation+6
1 year ago
Concierge preview

Concierge

GitHublixmk/concierge

Concierge Toolkit: Physical Access Control Identification and Exploitation

embedded-systems-securityexploitationhardware-hacking+5
1198 years ago
network-security-snort preview

network-security-snort

GitHubtaisa456/network-security-snort

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

defensive-toolseducationexploitation+6
4 months ago
connectwise-automate-AiTM-rce preview

connectwise-automate-AiTM-rce

GitHubsynap5e/connectwise-automate-aitm-rce

Writeup and code for CVE-2025-11492, CVE-2025-11493 - RCE in ConnctWise Automate RMM via Adversary-in-the-Middle

command-and-controleducationexploitation+8
110 months ago
CVE-2021-43798_exploit preview

CVE-2021-43798_exploit

GitHubaymenbouferroum/cve-2021-43798_exploit

Exploit for Grafana directory traversal (CVE-2021-43798) allowing local file read via crafted plugin path. Includes usage instructions and references.

exploitationinformation-gatheringpenetration-testing+2
14 years ago
inspect_petri preview

inspect_petri

GitHubmeridianlabs-ai/inspect_petri

An alignment auditing agent capable of quickly exploring alignment hypothesis

adversarial-attackai-securityeducation+4
1.3k27 days ago
BSF preview

BSF

GitHubtklab-tud/bsf

Botnet Simulation Framework

educationmalware-analysisnetwork-security+3
786 years ago
CVE-2021-43798-EXPLOIT preview

CVE-2021-43798-EXPLOIT

GitHubk3ystr0k3r/cve-2021-43798-exploit

A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal

educationexploitationinformation-gathering+3
42 years ago
CVE-2007-2447-Exploitation-SIEM-Detection-Lab preview

CVE-2007-2447-Exploitation-SIEM-Detection-Lab

GitHubharshiys/cve-2007-2447-exploitation-siem-detection-lab

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

educationexploitationexploit-frameworks+7
1 month ago
Previous12…100Next