Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
387 results
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
1
1 day ago
pupy preview

pupy

GitHubalessandroz/pupy

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

command-and-controldata-exfiltrationlateral-movement+7
918 years ago
RemotePotato0 preview

RemotePotato0

GitHubantoniococo/remotepotato0

Windows Privilege Escalation from User to Domain Admin.

authenticationexploitationlateral-movement+2
1.5k3 years ago
CVE-2026-50343-InstallService-EoP preview

CVE-2026-50343-InstallService-EoP

GitHubrat5ak/cve-2026-50343-installservice-eop

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

binary-exploitationeducationexploitation+3
481 month ago
nishang preview

nishang

GitHubsamratashok/nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

command-and-controldata-exfiltrationexploitation+9
10.1k3 years ago
pacu preview

pacu

GitHubrhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

cloud-securitydata-exfiltrationexploit-frameworks+5
5.3k4 months ago
Seatbelt preview

Seatbelt

GitHubghostpack/seatbelt

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

defensive-toolsinformation-gatheringpenetration-testing+5
4.7k1 year ago
EQGRP preview

EQGRP

GitHubx0rz/eqgrp

Decrypted content of eqgrp-auction-file.tar.xz

command-and-controldata-exfiltrationexploitation+8
4.2k9 years ago
OffensiveNim preview

OffensiveNim

GitHubbyt3bl33d3r/offensivenim

My experiments in weaponizing Nim (https://nim-lang.org/)

binary-exploitationcode-analysiscommand-and-control+8
3.1k2 years ago
SharpCollection preview

SharpCollection

GitHubflangvik/sharpcollection

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

curated-resourcesexploitationlateral-movement+6
3.0k22 days ago
juicy-potato preview

juicy-potato

GitHubohpe/juicy-potato

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT…

exploitationpenetration-testingpost-exploitation+1
2.8k5 years ago
Active-Directory-Exploitation-Cheat-Sheet preview

Active-Directory-Exploitation-Cheat-Sheet

GitHubintegration-it/active-directory-exploitation-cheat-sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

curated-resourcesdata-exfiltrationeducation+6
2.8k1 year ago
SSH-Snake preview
Archived

SSH-Snake

GitHubmegamansec/ssh-snake

SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.

information-gatheringlateral-movementnetwork-mapping+5
2.3k4 months ago
redamon preview

redamon

GitHubsamugit83/redamon

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

ai-securityexploit-frameworkslateral-movement+8
2.3k18h 45m ago
GodPotato preview

GodPotato

GitHubbeichendream/godpotato

DCOM-based privilege escalation tool for Windows Server 2012-2022 and Windows 8-11, elevating users with ImpersonatePrivilege to NT AUTHORITY\SYSTEM…

exploitationpenetration-testingpost-exploitation+1
2.3k2 years ago
unshackle preview
Archived

unshackle

GitHubfadi002/unshackle

Open-source tool to bypass windows and linux passwords from bootable usb

authentication-authorizationeducationpassword-attacks+3
2.0k2 years ago
AD_Miner preview

AD_Miner

GitHubad-security/ad_miner

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

configuration-auditingeducationinformation-gathering+6
1.6k5 months ago
AggressorScripts preview

AggressorScripts

GitHubharleyqu1nn/aggressorscripts

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

command-and-controlinformation-gatheringpayload-generation+5
1.5k3 years ago
Previous12…22Next