Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
SharpExchange preview

SharpExchange

GitHubceramicskate0/sharpexchange

C# Tool to interact with MS Exchange based on MS docs

data-exfiltrationeducationinformation-gathering+4
102
3 years ago
Change-Lockscreen preview

Change-Lockscreen

GitHubnccgroup/change-lockscreen

Offensive tool to trigger network authentications as SYSTEM

exploitationpost-exploitationprivilege-escalation+1
1444 years ago
shouganaiyo-loader preview

shouganaiyo-loader

GitHubnccgroup/shouganaiyo-loader

shouganaiyo-loader is a cross-platform Frida-based Node.js command-line tool that forces Java processes to load a Java/JVMTI agent regardless of…

exploitationids-ips-evasionpenetration-testing+2
394 years ago
Follina_Exploiter_CLI preview

Follina_Exploiter_CLI

GitHubhrishikesh7665/follina_exploiter_cli

Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)

command-and-controlexploitationpayload-generation+4
344 years ago
CVE-2026-4631-cockpit-RCE preview

CVE-2026-4631-cockpit-RCE

GitHubexdev994/cve-2026-4631-cockpit-rce

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

command-and-controlexploitationinformation-gathering+6
2 months ago
godofwar preview

godofwar

GitHubkingsabri/godofwar

GodOfWar - Malicious Java WAR builder with built-in payloads

exploitationpayload-developmentpayload-generation+3
1257 years ago
shepard preview

shepard

GitHubd3adzo/shepard

In progress persistent download/upload/execution tool using Windows BITS.

command-and-controldata-exfiltrationpersistence-mechanisms+3
415 years ago
pingtunnel preview

pingtunnel

GitHubesrrhs/pingtunnel

Pingtunnel is a tool that send TCP/UDP traffic over ICMP

ids-ips-evasionnetwork-securitypenetration-testing+1
3.7k11 days ago
QRExfil preview

QRExfil

GitHubshell-company/qrexfil

This tool is a command line utility that allows you to convert any binary file into a QRcode movie. The data can then be reassembled visually…

data-exfiltrationred-teaming
2823 years ago
TLDHunt preview

TLDHunt

GitHubyuyudhn/tldhunt

Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

dns-subdomain-enumerationinformation-gatheringosint+2
1851 year ago
PoisonApple preview

PoisonApple

GitHubcyborgsecurity/poisonapple

CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

persistence-mechanismspost-exploitationred-teaming
2294 years ago
LAZYPARIAH preview
Archived

LAZYPARIAH

GitHuboctetsplicer/lazypariah

A tool for generating reverse shell payloads on the fly.

command-and-controlctfexploitation+5
16 months ago