Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2446 results
MHDDoS preview

MHDDoS

GitHubmatrixtm/mhddos

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

dns-analysisids-ips-evasionnetwork-mapping+4
16.7k
8 days ago
strix preview

strix

GitHubusestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

ai-securityapi-security-testingcode-analysis+9
62.5k1 day ago
ESP32Marauder preview

ESP32Marauder

GitHubjustcallmekoko/esp32marauder

A suite of WiFi/Bluetooth offensive and defensive tools for the ESP32

bluetooth-securitydefensive-toolsembedded-systems-security+6
12.4k6 days ago
Modlishka preview

Modlishka

GitHubdrk1wi/modlishka

Modlishka. Reverse Proxy.

authenticationimpersonation-toolspenetration-testing+6
5.4k1 month ago
hoaxshell preview

hoaxshell

GitHubt3l3machus/hoaxshell

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

command-and-controlexploitationpayload-generation+5
3.5k1 year ago
ZORG-Jailbreak-Prompt-Text preview

ZORG-Jailbreak-Prompt-Text

GitHubtrinib/zorg-jailbreak-prompt-text

Bypass restricted and censored content on AI chat prompts 😈

adversarial-attackai-securitycurated-resources+2
3071 year ago
RedditC2 preview

RedditC2

GitHubkleiton0x00/redditc2

Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

command-and-controlexploitationpayload-development+1
2773 years ago
ghostsplice preview

ghostsplice

GitHubasset-group/ghostsplice

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

adversarial-attackai-securitydata-exfiltration+3
71 month ago
Macrome preview

Macrome

GitHubmichaelweber/macrome

Excel Macro Document Reader/Writer for Red Teamers & Analysts

binary-analysisexploitationmalware-analysis+5
5234 years ago
frp preview

frp

GitHubfatedier/frp

A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.

network-securitypenetration-testingred-teaming+1
109.4k5 days ago
Tater preview

Tater

GitHubkevin-robertson/tater

Tater is a PowerShell implementation of the Hot Potato Windows Privilege Escalation exploit from @breenmachine and @foxglovesec

exploitationpenetration-testingprivilege-escalation+1
45610 years ago
PEASS-ng preview

PEASS-ng

GitHubpeass-ng/peass-ng

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

educationexploitationexploit-frameworks+7
20.5k1 day ago
Invoke-BadSuccessor.ps1 preview

Invoke-BadSuccessor.ps1

GitHubb5null/invoke-badsuccessor.ps1

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

authenticationexploitationpenetration-testing+4
473 months ago
PyRIT preview

PyRIT

GitHubmicrosoft/pyrit

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

adversarial-attackai-securitymachine-learning+2
4.5k15h 54m ago
Windows-RCE-exploits preview

Windows-RCE-exploits

GitHubsmgorelik/windows-rce-exploits

The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are…

educationexploitationexploit-frameworks+2
7462 years ago
notionterm preview

notionterm

GitHubariary/notionterm

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

command-and-controlexploitationpayload-generation+3
1383 years ago
BlackSnufkin preview

BlackSnufkin

GitHubblacksnufkin/blacksnufkin

Red team operator and malware developer specializing in evasion techniques, reverse engineering, and initial access operations. Active CVE researcher…

educationexploitationmalware-analysis+3
23 months ago
CVE-2025-49113-Roundcube_1.6.10 preview

CVE-2025-49113-Roundcube_1.6.10

GitHubcyberquestor-infosec/cve-2025-49113-roundcube_1.6.10

Authenticated remote code execution exploit for Roundcube 1.6.10 (CVE-2025-49113). Delivers a reverse shell via a crafted PHP payload through the…

educationexploitationpenetration-testing+3
1 year ago
Previous12…100Next