Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
RedTeaming-Tactics-and-Techniques preview

RedTeaming-Tactics-and-Techniques

GitHubmantvydasb/redteaming-tactics-and-techniques

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

educationexploitationlabs-practice+8
4.7k2 months ago
CVE-2025-4275 preview

CVE-2025-4275

GitHubthemalwareguardian/cve-2025-4275

Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…

binary-analysiseducationexploitation+5
18 days ago
CVE-2026-25250 preview

CVE-2026-25250

GitHubthemalwareguardian/cve-2026-25250

Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without…

binary-analysiseducationexploitation+3
118 days ago
Vidar-Stealer-Reverse-Engineering preview

Vidar-Stealer-Reverse-Engineering

GitHubkaandemir993/vidar-stealer-reverse-engineering

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

binary-analysiseducationforensics+7
21 month ago
CVE-2025-6218-WinRAR-RCE-POC preview

CVE-2025-6218-WinRAR-RCE-POC

GitHubchrxstxqn/cve-2025-6218-winrar-rce-poc

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

binary-exploitationeducationexploitation+6
28 months ago
CVE-2025-8088 preview

CVE-2025-8088

GitHubnuky-alt/cve-2025-8088

Proof-of-concept exploit and technical analysis for a WinRAR path traversal vulnerability enabling code execution via crafted archives with binary…

binary-exploitationeducationexploitation+4
10 months ago
CVE-2019-11043-Vulnerability preview

CVE-2019-11043-Vulnerability

GitHubmagentabear/cve-2019-11043-vulnerability

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

educationexploitationlabs-practice+8
9 months ago
MalDev preview

MalDev

GitHubcaptmag/maldev

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

anti-boteducationencryption-decryption-tools+9
1024 days ago
PEASS-ng preview

PEASS-ng

GitHubpeass-ng/peass-ng

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

educationexploitationexploit-frameworks+7
20.4k2 days ago
byob preview

byob

GitHubmalwaredllc/byob

An open-source post-exploitation framework for students, researchers and developers.

command-and-controleducationpacket-sniffing-analysis+6
9.5k14 days ago
ghost preview

ghost

GitHubahxr/ghost

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

command-and-controleducationmalware-analysis+5
1.1k8 years ago
botnet-hackpack preview

botnet-hackpack

GitHubtreehacks/botnet-hackpack

Build a basic Command & Control botnet in C

command-and-controleducationmalware-analysis+3
4057 years ago
VectorKernel preview

VectorKernel

GitHubdaem0nc0re/vectorkernel

PoCs for Kernelmode rootkit techniques research.

educationexploitationmalware-analysis+3
4445 months ago
gmailc2 preview

gmailc2

GitHubmachine1337/gmailc2

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

command-and-controleducationpayload-generation+4
49011 months ago
conquest preview

conquest

GitHubjakobfriedl/conquest

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

command-and-controleducationexploit-frameworks+7
4211 month ago
spyrat preview

spyrat

GitHubm4sc3r4n0/spyrat

Python Remote Access Trojan

command-and-controleducationpayload-development+3
1499 years ago
ConTroll_Remote_Access_Trojan preview

ConTroll_Remote_Access_Trojan

GitHublithium876/controll_remote_access_trojan

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

command-and-controleducationinformation-gathering+7
1038 years ago
Umbra preview

Umbra

GitHubh3xduck/umbra

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

command-and-controleducationencryption-decryption-tools+6
1364 years ago
Previous123Next