Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
KrbRelay preview

KrbRelay

GitHubcube0x0/krbrelay

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

authenticationexploitationlateral-movement+2
955
4 years ago
attackgen preview

attackgen

GitHubmrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

ai-securityctfeducation+5
1.2k1 day ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
184 days ago
CVE-2022-25262 preview

CVE-2022-25262

GitHubyuriisanin/cve-2022-25262

PoC + vulnerability details for CVE-2022-25262 / JetBrains Hub single-click SAML response takeover

authenticationexploitationpenetration-testing+3
174 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubka7ana/cve-2023-23397

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

authenticationexploitationpenetration-testing+3
403 years ago
CVE-2024-54819 preview

CVE-2024-54819

GitHubpartywavesec/cve-2024-54819

CVE-2024-54819

exploitationpenetration-testingred-teaming+2
11 year ago
MouseJack preview

MouseJack

GitHubsecurityward/mousejack

All the details and steps needed to perform tactical mousejacking using Autojack

exploitationpayload-generationred-teaming+2
157 years ago
Blackash-CVE-2025-33073 preview

Blackash-CVE-2025-33073

GitHubirjfifndn-prog/blackash-cve-2025-33073

CVE-2025-33073

command-and-controlexploitationlateral-movement+4
10 months ago
HttpRemotingObjRefLeak preview

HttpRemotingObjRefLeak

GitHubcodewhitesec/httpremotingobjrefleak

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

code-analysisexploitationpayload-development+4
922 years ago
watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 preview

watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-preauth-rce-cve-2026-8452

CVE-2026-8452 PreAuth RCE

exploitationpayload-developmentred-teaming+3
631 month ago
CVE-2024-48990-Exploit preview

CVE-2024-48990-Exploit

GitHubally-petitt/cve-2024-48990-exploit

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

exploitationpayload-developmentpenetration-testing+3
51 year ago
Mindmap preview

Mindmap

GitHubignitetechnologies/mindmap

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give…

curated-resourceseducationlearning-paths-courses+2
9.3k2 months ago
CVE-2017-16778-Intercom-DTMF-Injection preview

CVE-2017-16778-Intercom-DTMF-Injection

GitHubbreaktoprotect/cve-2017-16778-intercom-dtmf-injection

A coordinated disclosure and security advisory on Fermax Intercom DTML Injection vulneraiblity. Special thanks to Fermax International for prompt…

embedded-systems-securityexploitationhardware-hacking+6
226 years ago
Amsi_Bypass_In_2023 preview

Amsi_Bypass_In_2023

GitHubsenzee1984/amsi_bypass_in_2023

Amsi Bypass payload that works on Windwos 11

adversarial-attackexploitationids-ips-evasion+4
3783 years ago
Fortijump-Exploit-CVE-2024-47575 preview

Fortijump-Exploit-CVE-2024-47575

GitHubwatchtowrlabs/fortijump-exploit-cve-2024-47575

Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

exploitationpenetration-testingred-teaming+3
971 year ago
metabase-cve-2023-38646 preview

metabase-cve-2023-38646

GitHubkushiro45/metabase-cve-2023-38646

Repo contains the PoC and steps to reproduce cve 2023-38646

exploitationpayload-developmentpenetration-testing+3
2 months ago
ModuleStomping preview

ModuleStomping

GitHubwithsecurelabs/modulestomping

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

binary-analysismalware-analysisred-teaming
1237 years ago
Ashwesker-CVE-2026-21858 preview

Ashwesker-CVE-2026-21858

GitHubbgarz929/ashwesker-cve-2026-21858

Exploit for CVE-2026-21858, a critical unauthenticated content-type parsing flaw in n8n allowing arbitrary file read, credential theft, and remote…

exploitationpenetration-testingred-teaming+3
8 months ago
Previous123Next