Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
361 results
keebcap preview

keebcap

GitHubsynacktiv/keebcap

Win32 keylogger that supports all (non-ime using) languages correctly

data-exfiltrationinformation-gatheringpassword-attacks+2
56
2 years ago
reave preview

reave

GitHubpsmths/reave

WIP Post-exploitation framework tailored for hypervisors.

command-and-controldata-exfiltrationexploit-frameworks+8
502 years ago
Schwarze-Sonne-RAT preview

Schwarze-Sonne-RAT

GitHubmwsrc/schwarze-sonne-rat

SS-RAT (Schwarze-Sonne-Remote-Access-Trojan)

command-and-controldata-exfiltrationlateral-movement+6
299 years ago
teletunnel preview

teletunnel

GitHubmhdgning131/teletunnel

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

command-and-controldata-exfiltrationids-ips-evasion+7
444 months ago
Invoke-HiveNightmare preview

Invoke-HiveNightmare

GitHubwiredpulse/invoke-hivenightmare

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version…

data-exfiltrationexploitationpost-exploitation+2
355 years ago
osx-password-dumper preview

osx-password-dumper

GitHubjeanpeyremesmots/osx-password-dumper

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

ctfpassword-crackingpenetration-testing+2
531 year ago
xcavator preview

xcavator

GitHubnccgroup/xcavator

A network data locater using credentials obtained during penetration tests

data-exfiltrationinformation-gatheringnetwork-security+3
3312 years ago
bat preview

bat

GitHubrhzv0/bat
command-and-controldata-exfiltrationlateral-movement+5
363 months ago
SkyRAT preview

SkyRAT

GitHubyschgroup/skyrat

SkyRAT - Powershell Remote Administration Tool

command-and-controldata-exfiltrationlateral-movement+5
348 years ago
siphondns preview

siphondns

GitHubttpreport/siphondns

Covert data exfiltration via DNS

adversarial-attackcommand-and-controldata-exfiltration+3
531 year ago
RedbloodC2 preview

RedbloodC2

GitHubkira2040k/redbloodc2
command-and-controldata-exfiltrationencryption-decryption-tools+5
293 years ago
XeytanWin32-RAT preview

XeytanWin32-RAT

GitHubmelardev/xeytanwin32-rat

WORK IN PROGRESS. RAT written in C++ using Win32 API

command-and-controldata-exfiltrationexploitation+8
206 years ago
dicerosbicornis preview

dicerosbicornis

GitHubmaldevel/dicerosbicornis

A fully featured Windows backdoor that uses email as a C&C server

command-and-controldata-exfiltrationencryption-decryption-tools+5
169 years ago
TospoVirus preview

TospoVirus

GitHubcatatonicprime/tospovirus

A WiFi Pineapple infecting worm.

command-and-controldata-exfiltrationexploitation+5
1711 years ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
CVE-2026-15409 preview

CVE-2026-15409

GitHubch4120n/cve-2026-15409

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

data-exfiltrationexploitationpenetration-testing+4
317 days ago
Malicious-MCP preview

Malicious-MCP

GitHubquinnbast/malicious-mcp

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

ai-securitycommand-and-controldata-exfiltration+8
84 months ago
glass-cage-i18-2025-24085-and-cve-2025-24201 preview

glass-cage-i18-2025-24085-and-cve-2025-24201

GitHub5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

binary-exploitationdata-exfiltrationeducation+9
511 months ago
Previous1…171819…21Next