Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
118 results
CVE-2024-51793 preview

CVE-2024-51793

GitHub0axz-tools/cve-2024-51793

Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells,…

exploitationpayload-developmentpenetration-testing+3
10 months ago
LSTAR-EN preview

LSTAR-EN

GitHubmoscowchill/lstar-en

LSTAR - CobaltStrike Translated to EN

command-and-controlexploitationids-ips-evasion+9
233 years ago
DuplicateDump preview

DuplicateDump

GitHubhagrid29/duplicatedump

Dumping LSASS with a duplicated handle from custom LSA plugin

post-exploitationprivilege-escalationred-teaming
2074 years ago
nate158g-m-w-n-l-p-d-a-o-e preview

nate158g-m-w-n-l-p-d-a-o-e

GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

exploit-frameworkspayload-generationpenetration-testing-frameworks+3
144 years ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.7k6h 10m ago
IoT-Implant-Toolkit preview

IoT-Implant-Toolkit

GitHubarthastang/iot-implant-toolkit

Toolkit for implant attack of IoT devices

binary-analysisembedded-systems-securityexploitation+8
1358 years ago
nowafpls preview

nowafpls

GitHubassetnote/nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

ids-ips-evasionpenetration-testingred-teaming+3
1.5k1 year ago
CVE-2026-31908 preview

CVE-2026-31908

GitHubmehranturk/cve-2026-31908

Proof-of-concept exploit for CVE-2026-31908, a critical header injection vulnerability in Apache APISIX, demonstrating authentication bypass and…

educationexploitationpenetration-testing+3
14 months ago
doppelganger_assistant preview

doppelganger_assistant

GitHubtweathers-sec/doppelganger_assistant

Card calculator and Proxmark3 Plugin for writing and/or simulating every card type that Doppelgänger Community, Pro, Stealth, and MFAS support.

embedded-systems-securityencryption-decryption-toolshardware-hacking+5
328 months ago
ettercap preview

ettercap

GitHubettercap/ettercap

Ettercap Project

dns-analysisexploitationinformation-gathering+6
2.8k0 days ago
RedWarden preview
Archived

RedWarden

GitHubmgeeky/redwarden

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

command-and-controlexploit-frameworksids-ips-evasion+8
9983 years ago
cve-2026-82222-poc preview

cve-2026-82222-poc

GitHubudinchan/cve-2026-82222-poc

Proof-of-concept exploit for CVE-2026-82222, an unauthenticated PHP object injection leading to remote code execution in GiveWP WordPress plugin…

exploitationpenetration-testingred-teaming+2
5 days ago
nox-framework preview

nox-framework

GitHubnox-project/nox-framework

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

crawlerdata-exfiltrationdigital-forensics+8
3244 months ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
CVE-2026-21962 preview

CVE-2026-21962

GitHubzeetee1235/cve-2026-21962

Verified PoC and analysis for CVE-2026-21962, an access-control bypass in Oracle HTTP Server/WebLogic Proxy Plug-in via URI normalization…

exploitationpenetration-testingred-teaming+3
38 days ago
apache-struts-cve-2017-9805 preview

apache-struts-cve-2017-9805

GitHubrvermeulen/apache-struts-cve-2017-9805

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

code-analysisexploitationpenetration-testing+3
5 years ago
CVE-2024-7627 preview

CVE-2024-7627

GitHublkmn1/cve-2024-7627

Proof-of-concept exploit for CVE-2024-7627, an unauthenticated remote code execution vulnerability in Bit File Manager WordPress plugin. Automates…

exploitationpayload-developmentpenetration-testing+3
10 months ago
CVE-2026-8181-PoC preview

CVE-2026-8181-PoC

GitHubsquamity/cve-2026-8181-poc

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

authenticationdefensive-toolseducation+5
1 month ago
Previous1234567Next