Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
275 results
Xenotix-xBOT preview

Xenotix-xBOT

GitHubajinabraham/xenotix-xbot

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

command-and-controlexploitationinformation-gathering+4
28
8 years ago
LALIN preview
Archived

LALIN

GitHubscreetsec/lalin

this script automatically install any package for pentest with uptodate tools , and lazy command for run the tools like lazynmap , install another…

information-gatheringpenetration-testingreconnaissance+3
3819 years ago
RadareEye preview

RadareEye

GitHubsouravbaghz/radareeye

Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.

bluetooth-securityiot-securityreconnaissance+3
3864 years ago
eviltree preview

eviltree

GitHubt3l3machus/eviltree

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

information-gatheringpost-exploitationprivilege-escalation+3
4131 year ago
BRC4-BOF-Artillery preview

BRC4-BOF-Artillery

GitHubparanoidninja/brc4-bof-artillery

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

command-and-controlencryption-decryption-toolshash-analysis+5
15111 months ago
impacket preview

impacket

GitHubfortra/impacket

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

authenticationcommand-and-controldatabase-security+17
16.1k4 days ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubabhishekmorla/cve-2022-26134

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

exploitationinformation-gatheringpenetration-testing+3
84 years ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubobscura-cert/cve-2025-33073

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

authenticationcommand-and-controldns-analysis+7
11 year ago
WMIcmd preview

WMIcmd

GitHubnccgroup/wmicmd

A command shell wrapper using only WMI for Microsoft Windows

information-gatheringlateral-movementpenetration-testing+3
3339 years ago
CVE-2015-1635 preview

CVE-2015-1635

GitHubcappricio-securities/cve-2015-1635

Microsoft Windows 'HTTP.sys' - Remote Code Execution

exploitationinformation-gatheringpenetration-testing+3
12 years ago
wappalyzer-next preview

wappalyzer-next

GitHubs0md3v/wappalyzer-next

detect technologies with wappalyzer alternative

crawlerinformation-gatheringreconnaissance+1
4205 days ago
Adrenaline preview

Adrenaline

GitHubatomiczsec/adrenaline

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

command-and-controldefensive-toolsinformation-gathering+7
3191 month ago
API-SPY-API-PROBE preview

API-SPY-API-PROBE

GitHubaustinjump-sec/api-spy-api-probe

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

api-security-testingcrawlerinformation-gathering+4
54 months ago
portscan-CVE-2026-41940 preview

portscan-CVE-2026-41940

GitHubamirrezamarzban/portscan-cve-2026-41940

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

information-gatheringnetwork-securitypenetration-testing+3
15 months ago
PHP_8.1.x_Exploit preview

PHP_8.1.x_Exploit

GitHubgl1tch0x1/php_8.1.x_exploit

Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)

command-and-controlcrawlerexploitation+7
15 months ago
xurlfind3r preview

xurlfind3r

GitHubhueristiq/xurlfind3r

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

information-gatheringosintpenetration-testing+2
72310 months ago
xcrawl3r preview

xcrawl3r

GitHubhueristiq/xcrawl3r

Recursively spider webpages to discover all URLs by following links, parsing sitemaps, and robots.txt files. Ideal for security reconnaissance and…

crawlerinformation-gatheringpenetration-testing+2
11110 months ago
cua-kit preview

cua-kit

GitHubpreludeorg/cua-kit

Tools for attacking Computer Use Agents

ai-securitycommand-and-controlexploitation+7
338 months ago
Previous12…16Next