Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
159 results
Credential-Hunting preview

Credential-Hunting

GitHubnecr00/credential-hunting

CredsHunter - Credential Hunting scripts for Windows and Linux OS

forensicsincident-responseinformation-gathering+7
175
2 days ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubnxploited/cve-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

exploitationinformation-gatheringpost-exploitation+3
4 days ago
NetExec preview

NetExec

GitHubpennyw0rth/netexec

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

information-gatheringnetwork-securitypenetration-testing+2
5.8k4 days ago
Adrenaline preview

Adrenaline

GitHubatomiczsec/adrenaline

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

command-and-controldefensive-toolsinformation-gathering+7
3135 days ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
10 days ago
ghosthound preview

ghosthound

GitHubjvbotelho/ghosthound

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

exploitationinformation-gatheringlateral-movement+5
4311 days ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
9812 days ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide
exploitationinformation-gatheringlateral-movement+6
1616 days ago
couchdb-exploit preview

couchdb-exploit

GitHubdarabium/couchdb-exploit

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

exploitationinformation-gatheringpenetration-testing+4
17 days ago
tactical-exploitation preview

tactical-exploitation

GitHub0xdea/tactical-exploitation

Modern tactical exploitation toolkit.

exploitationinformation-gatheringosint+8
86618 days ago
Nemesis preview

Nemesis

GitHubspecterops/nemesis

Centralized data enrichment platform for offensive security assessments that ingests, enriches, and enables collaborative analysis of collected files…

information-gatheringosintpenetration-testing+3
99520 days ago
adPEAS preview

adPEAS

GitHub61106960/adpeas

Powershell tool to automate Active Directory enumeration.

authenticationexploitationinformation-gathering+6
1.4k24 days ago
hackingtool preview

hackingtool

GitHubz4nzu/hackingtool

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

cloud-securityexploitationforensics+9
79.0k25 days ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
128 days ago
keelog-bof preview

keelog-bof

GitHubjakobfriedl/keelog-bof

Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.

information-gatheringpassword-crackingpost-exploitation+2
5028 days ago
fsociety preview

fsociety

GitHubmanisso/fsociety

fsociety Hacking Tools Pack – A Penetration Testing Framework

exploitationinformation-gatheringpassword-attacks+6
12.3k1 month ago
nimrm preview

nimrm

GitHubblue0x1/nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

authenticationcommand-and-controlinformation-gathering+6
51 month ago
toastnotify-bof preview

toastnotify-bof

GitHubbrmkit/toastnotify-bof

abusing windows toast notifications for fun and user manipulation

information-gatheringpayload-developmentphishing+3
1041 month ago
Previous12…9Next