Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
tfo-connect-bypass preview

tfo-connect-bypass

GitHub4n4s4zi/tfo-connect-bypass

Using TCP Fast Open to bypass syscall-based networking rules (CVE-2026-63828/CVE-2026-72243 PoC)

exploitationids-ips-evasionnetwork-security+3
1 day ago
Mythic preview

Mythic

GitHubits-a-feature/mythic

A collaborative, multi-platform, red teaming framework

command-and-controldata-exfiltrationexploitation+9
4.8k1 day ago
nimrm preview

nimrm

GitHubblue0x1/nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

authenticationcommand-and-controlinformation-gathering+6
61 month ago
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

dynamic-code-analysiseducationencryption-decryption-tools+7
472 months ago
PhantomCtx preview

PhantomCtx

GitHubr3xmax/phantomctx

Activation Context Hijacking Evasion Tool

binary-exploitationexploitationpayload-development+3
3052 months ago
Shocker-TJNULL-OSCP- preview

Shocker-TJNULL-OSCP-

GitHubr3fr4kt/shocker-tjnull-oscp-

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

educationexploitationlabs-practice+6
3 months ago
Stardust preview

Stardust

GitHubcracked5pider/stardust

A modern 32/64-bit position independent implant template

binary-exploitationexploitationpayload-development+4
1.4k3 months ago
CVE-2025-32462 preview

CVE-2025-32462

GitHubcryingn/cve-2025-32462

A easy sudo poc by cryingn.

exploitationpenetration-testingpost-exploitation+3
124 months ago
HTB-TwoMillion-Writeup preview

HTB-TwoMillion-Writeup

GitHubkarimelsheikh1/htb-twomillion-writeup

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

command-and-controlctfeducation+8
4 months ago
pypykatz preview

pypykatz

GitHubskelsec/pypykatz

Mimikatz implementation in pure Python

authenticationdigital-forensicsencryption-decryption-tools+4
3.4k5 months ago
TotalRecall preview

TotalRecall

GitHubxaitax/totalrecall

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

data-exfiltrationexploitationinformation-gathering+5
1655 months ago
CVE-2025-62429 preview

CVE-2025-62429

GitHubdrkim-dev/cve-2025-62429

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

code-analysisexploitationpayload-development+5
15 months ago
BloodHound-Legacy preview

BloodHound-Legacy

GitHubspecterops/bloodhound-legacy

Six Degrees of Domain Admin

information-gatheringlateral-movementpenetration-testing+4
10.6k6 months ago
MAAD-AF preview

MAAD-AF

GitHubvectra-ai-research/maad-af

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

adversarial-attackcloud-securitydata-exfiltration+6
4317 months ago
cve-2025-3248-exploit preview

cve-2025-3248-exploit

GitHubdrackyjr/cve-2025-3248-exploit

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

code-analysiscommand-and-controleducation+8
39 months ago
APEX preview

APEX

GitHubluemmelsec/apex

Azure Post Exploitation Framework

cloud-securitydata-exfiltrationexploit-frameworks+4
24810 months ago
WinPwn preview

WinPwn

GitHubs3cur3th1ssh1t/winpwn

Automation for internal Windows Penetrationtest / AD-Security

exploitationpenetration-testingpenetration-testing-frameworks+4
3.7k1 year ago
LdrShuffle preview

LdrShuffle

GitHubrwxstoned/ldrshuffle

Code execution/injection technique using DLL PEB module structure manipulation

binary-exploitationcode-analysisexploitation+6
2871 year ago
Previous123Next