Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
48
20 days ago
malicious-pdf preview

malicious-pdf

GitHubjonaslejon/malicious-pdf

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

data-exfiltrationeducationexploitation+6
4.5k1 month ago
EvilnoVNC preview

EvilnoVNC

GitHubjoelgmsec/evilnovnc

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

information-gatheringpassword-crackingphishing+3
1.2k1 year ago
ntlm_theft preview

ntlm_theft

GitHubgreenwolf/ntlm_theft

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

information-gatheringpassword-attackspenetration-testing+2
1.5k26 days ago
htshells preview

htshells

GitHubwireghoul/htshells

Self contained htaccess shells and attacks

exploitationinformation-gatheringpayload-generation+5
1.1k4 years ago
sage preview

sage

GitHubgendigitalinc/sage

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

ai-securitycode-analysisdefensive-tools+6
31019 days ago
pmotadeee preview

pmotadeee

GitHubpmotadeee/pmotadeee

Bora Jogar?

ctfeducationlabs-practice+3
154 days ago
CVE-2023-49052 preview

CVE-2023-49052

GitHubcyber-wo0dy/cve-2023-49052

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

exploitationmalware-analysisphishing-tools+2
2 years ago
WEAPONIZING-CVE-2024-4367 preview

WEAPONIZING-CVE-2024-4367

GitHubexfil0/weaponizing-cve-2024-4367

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

educationexploitationpayload-generation+3
31 year ago
cromos preview

cromos

GitHubjimywork/cromos

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

command-and-controldata-exfiltrationlateral-movement+5
1248 years ago
vulnerable-PDF preview

vulnerable-PDF

GitHubnu11secur1ty/vulnerable-pdf

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

educationlabs-practicepayload-generation+3
112 years ago
PhishingKitHunter preview

PhishingKitHunter

GitHubt4d/phishingkithunter

Find phishing kits which use your brand/organization's files and image.

information-gatheringlog-analysisosint+3
2427 years ago
CVE-2018-25031 preview

CVE-2018-25031

GitHubafine-com/cve-2018-25031

.json and .yaml files used to exploit CVE-2018-25031

api-securityexploitationphishing-tools+3
21 year ago
BobTheSmuggler preview

BobTheSmuggler

GitHubthecyb3ralpha/bobthesmuggler

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

educationencryption-decryption-toolspayload-development+4
5961 year ago
CVE-2025-24054_CVE-2025-24071-PoC preview

CVE-2025-24054_CVE-2025-24071-PoC

GitHubhelidem/cve-2025-24054_cve-2025-24071-poc

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

educationexploitationlabs-practice+5
2211 months ago
CVE-2022-44666 preview

CVE-2022-44666

GitHubj00sean/cve-2022-44666

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

exploitationpayload-developmentphishing-tools+2
1543 years ago
DATA preview

DATA

GitHubhadojae/data

Credential Phish Analysis and Automation

information-gatheringosintphishing+2
998 years ago
CVE-2025-50154-Aggressor-Script preview

CVE-2025-50154-Aggressor-Script

GitHubash1996x/cve-2025-50154-aggressor-script

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

command-and-controlctfeducation+9
11 year ago
Previous12Next