Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
90 results
PoisonApple preview

PoisonApple

GitHubcyborgsecurity/poisonapple

CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

persistence-mechanismspost-exploitationred-teaming
2294 years ago
MacShellSwift preview

MacShellSwift

GitHubcedowens/macshellswift

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

defensive-toolspenetration-testingpost-exploitation+2
1245 years ago
DynastyPersist preview

DynastyPersist

GitHubtrevohack/dynastypersist

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

ctfpenetration-testingpersistence-mechanisms+3
1611 year ago
Juicy-Potato-x86 preview

Juicy-Potato-x86

GitHubivanitlearning/juicy-potato-x86

Windows privilege escalation exploit that abuses service token impersonation to execute arbitrary commands with SYSTEM privileges, designed for x86…

exploitationpenetration-testingpost-exploitation+2
1336 years ago
ACEshark preview

ACEshark

GitHubt3l3machus/aceshark

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

configuration-auditinginformation-gatheringpenetration-testing+4
1511 year ago
Orwell-RAT-and-Botnet preview

Orwell-RAT-and-Botnet

GitHubcorrecthorsebatterystaple-sudo/orwell-rat-and-botnet

Orwell is a RAT and Botnet designed as a trio of programs.

command-and-controlpayload-generationpost-exploitation+2
319 years ago
Hawk preview

Hawk

GitHubprodefense/hawk

Golang tool designed to exfiltrate passwords found via the sshd and su services

data-exfiltrationinformation-gatheringpassword-attacks+3
3810 months ago
PSI_BOF preview

PSI_BOF

GitHubwhokilleddb/psi_bof

A BOF designed to inspect processes memory and addresses

binary-analysisdebuggersmemory-forensics+4
415 months ago
VQ-RefluxCore preview

VQ-RefluxCore

GitHubvulnquest58/vq-refluxcore

is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with…

binary-exploitationctfeducation+5
2 months ago
Fsociety-CVE-2024-0670-CheckMK-LPE preview

Fsociety-CVE-2024-0670-CheckMK-LPE

GitHubnikopmpm/fsociety-cve-2024-0670-checkmk-lpe

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

exploitationpenetration-testingpersistence-mechanisms+4
5 days ago
Mallicious-IOS-SHORTCUT-KEYLOGGER- preview

Mallicious-IOS-SHORTCUT-KEYLOGGER-

GitHubspiralbl0ck/mallicious-ios-shortcut-keylogger-

iOS Shortcut-based keylogger designed to capture keystrokes and exfiltrate data from compromised devices.

data-exfiltrationios-securitymobile-security+2
2 years ago
CVE-2023-52654 preview

CVE-2023-52654

GitHubfoxyproxys/cve-2023-52654

Automated privilege escalation script exploiting misconfigured setuid/sgid binaries, sudo, cron, and LD_PRELOAD on Unix systems. Designed for CTF and…

ctfexploitationpenetration-testing+3
2 years ago
honeybits preview
Archived

honeybits

GitHub0x4d31/honeybits

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

information-gatheringlateral-movementosint-social-engineering+5
2787 years ago
RefleXXion preview
Archived

RefleXXion

GitHubhlldz/reflexxion

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first…

defensive-toolsids-ips-evasionpersistence-mechanisms+3
4984 years ago
AD-Attack-Defense preview

AD-Attack-Defense

GitHubinfosecn1nja/ad-attack-defense

Attack and defend active directory using modern post exploitation adversary tradecraft activity

curated-resourcesdefensive-toolseducation+7
4.9k1 year ago
Privilege-Escalation preview

Privilege-Escalation

GitHubignitetechnologies/privilege-escalation

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

ctfcurated-resourceseducation+6
3.6k6 months ago
CDK preview

CDK

GitHubcdk-team/cdk

📦 Make security testing of K8s, Docker, and Containerd easier.

cloud-securitycontainer-escapecontainer-security+7
4.8k5 months ago
AsyncRAT-C-Sharp preview

AsyncRAT-C-Sharp

GitHubnyan-x-cat/asyncrat-c-sharp

Open-Source Remote Administration Tool For Windows C# (RAT)

command-and-controldata-exfiltrationpassword-cracking+5
3.0k2 years ago
Previous12345Next