Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
277 results
R2Socks preview

R2Socks

GitHubivancabrera02/r2socks

SOCKS5 proxy tunneled through Cloudflare R2 object storage, with Python and dependency-free C++ agents relaying TCP traffic via encrypted R2 objects…

command-and-controldata-exfiltrationencryption-decryption-tools+5
38
29 days ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
2616 days ago
reburp preview

reburp

GitHubforefy/reburp

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

ai-securityapi-security-testingfuzzing+7
11416 days ago
evillimiter preview

evillimiter

GitHubdavidsonrafaelk/evillimiter

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

ids-ips-evasioninformation-gatheringnetwork-mapping+4
91 month ago
frp preview

frp

GitHubfatedier/frp

A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.

network-securitypenetration-testingred-teaming+1
109.8k28 days ago
pentest-harness preview

pentest-harness

GitHubs1n6h/pentest-harness

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

ai-securitycommand-and-controlctf+7
40727 days ago
KDU preview

KDU

GitHubhfiref0x/kdu

Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

binary-exploitationdefensive-toolsexploitation+8
2.8k9 days ago
LocalStranger preview

LocalStranger

GitHubnbs32k/localstranger

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

binary-exploitationexploit-frameworkspayload-development+3
4017 days ago
RegPwn preview

RegPwn

GitHubmdsecactivebreach/regpwn

Windows local privilege escalation exploit targeting CVE-2026-24291, with support for Windows 10/11 and Server 2016-2022 for authorized security…

exploitationpenetration-testingpost-exploitation+3
2516 months ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicshash-analysis+8
11.0k1 year ago
not-a-mused preview

not-a-mused

GitHubpwardle/not-a-mused

Proof-of-concept exploiting an undocumented Muse dictation endpoint setting, letting a local unprivileged process redirect dictation traffic to…

data-exfiltrationeducationexploitation+3
4616 days ago
CVE-2025-50505 preview

CVE-2025-50505

GitHuba0yami/cve-2025-50505

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

command-and-controldns-analysisexploitation+8
200 years ago
qyvora-toha3ee preview

qyvora-toha3ee

GitHubqyvora/qyvora-toha3ee

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

exploitationnetwork-securityosint+9
48 days ago
MS10-059 preview

MS10-059

GitHubh3x0v3rl0rd/ms10-059

Standalone exploit for MS10-059 vulnerability in Windows Canonical Display Driver, enabling local privilege escalation.

binary-exploitationexploitationpayload-development+3
5 years ago
GTFOBins.github.io preview

GTFOBins.github.io

GitHubgtfobins/gtfobins.github.io

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

curated-resourceseducationpenetration-testing+3
13.7k4 months ago
CdpSvcLPE preview

CdpSvcLPE

GitHubsailay1996/cdpsvclpe

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

exploitationpayload-developmentpenetration-testing+3
2544 years ago
Storm-Breaker preview

Storm-Breaker

GitHubultrasecurity/storm-breaker

Social engineering tool [Access Webcam & Microphone & Location Finder] With {Py,JS,PHP}

information-gatheringosintphishing-tools+2
6.1k1 year ago
Suborner preview

Suborner

GitHubr4wd3r/suborner

Creates invisible Windows accounts with administrative privileges via direct SAM manipulation and RID hijacking, bypassing standard user management…

persistence-mechanismspost-exploitationprivilege-escalation+1
4691 year ago
Previous12…16Next