Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
87 results
nopowershell preview

nopowershell

GitHubbitsadmin/nopowershell

PowerShell rebuilt in C# for Red Teaming purposes

command-and-controlinformation-gatheringpost-exploitation+2
1.1k11 months ago
siemframework preview

siemframework

GitHubelevenpaths/siemframework

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

exploit-frameworksinformation-gatheringnetwork-mapping+7
426 years ago
ipwndfu preview

ipwndfu

GitHubaxi0mx/ipwndfu

open-source jailbreaking tool for many iOS devices

binary-exploitationexploitationhardware-security+5
7.4k2 years ago
EggShell preview

EggShell

GitHublucasjacks0n/eggshell

iOS/macOS/Linux Remote Administration Tool

command-and-controlexploitationinformation-gathering+7
1.8k8 years ago
redsnarf preview

redsnarf

GitHubnccgroup/redsnarf

RedSnarf is a pen-testing / red-teaming tool for Windows environments

command-and-controlexploitationhash-analysis+9
1.2k9 years ago
DumpGuard preview

DumpGuard

GitHubbytewreck/dumpguard

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

authenticationexploitationinformation-gathering+6
7485 months ago
D3m0n1z3dShell preview

D3m0n1z3dShell

GitHubmatheuzsecurity/d3m0n1z3dshell

Demonized Shell is an Advanced Tool for persistence in linux.

persistence-mechanismspost-exploitationprivilege-escalation+1
4591 year ago
PhantomCtx preview

PhantomCtx

GitHubr3xmax/phantomctx

Activation Context Hijacking Evasion Tool

binary-exploitationexploitationpayload-development+3
3113 months ago
mnemosyne preview

mnemosyne

GitHubnccgroup/mnemosyne

A Generic Windows Memory Scraping Tool

dynamic-analysis-sandboxingfuzzinginformation-gathering+2
699 years ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
332 months ago
Anvil preview

Anvil

GitHubshellkraft/anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

binary-analysisexploitationpenetration-testing+5
396 months ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
92 months ago
CVE-2026-1357-POC preview

CVE-2026-1357-POC

GitHubcybertechajju/cve-2026-1357-poc

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

data-exfiltrationexploitationpenetration-testing+5
97 months ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubexfil0/cve-2025-53770

A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE)…

command-and-controlexploitationids-ips-evasion+7
51 year ago
CVE-2025-48932-Invision-Community-SQLi-Exploit preview

CVE-2025-48932-Invision-Community-SQLi-Exploit

GitHubcerberusmrxi/cve-2025-48932-invision-community-sqli-exploit

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

data-exfiltrationexploitationinformation-gathering+6
12 months ago
gato preview
Archived

gato

GitHubpraetorian-inc/gato

GitHub Actions Pipeline Enumeration and Attack Tool

devsecopsexploitationinformation-gathering+7
95 months ago
hackingtool preview

hackingtool

GitHubz4nzu/hackingtool

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

cloud-securityexploitationforensics+9
80.8k1 month ago
SharpADWS preview

SharpADWS

GitHubwh0amitz/sharpadws

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

authenticationexploitationlateral-movement+6
6062 years ago
Previous12345Next