Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
Aggressor-Aggregator preview

Aggressor-Aggregator

GitHubgmh5225/aggressor-aggregator

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

penetration-testing-frameworksred-teamingscripting-automation
2 years ago
Heroinn preview

Heroinn

GitHubb23r0/heroinn

A cross platform C2/post-exploitation framework.

command-and-controlpayload-developmentpenetration-testing-frameworks+4
7113 years ago
TTPForge preview

TTPForge

GitHubfacebookincubator/ttpforge

Adversary simulation framework for authoring and automating attacker TTPs as repeatable YAML scenarios, helping red and blue teams validate detection…

adversarial-attackincident-responsepenetration-testing-frameworks+2
43920 days ago
CoercedPotatoRDLL preview

CoercedPotatoRDLL

GitHubsokarepo/coercedpotatordll

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

exploitationpayload-developmentpenetration-testing+4
2272 years ago
specula preview

specula

GitHubtrustedsec/specula
command-and-controlpenetration-testing-frameworkspersistence-mechanisms+2
2371 year ago
tap preview

tap

GitHubtrustedsec/tap

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

command-and-controlpenetration-testing-frameworkspersistence-mechanisms+3
5043 years ago
CVE-2024-49113 preview

CVE-2024-49113

GitHubsafebreach-labs/cve-2024-49113

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

exploitationpenetration-testingred-teaming+1
5211 year ago
autopwn preview

autopwn

GitHubnccgroup/autopwn

Specify targets and run sets of tools against them

penetration-testingpenetration-testing-frameworksreconnaissance+2
3897 years ago
async-pico-hub preview

async-pico-hub

GitHubnccgroup/async-pico-hub

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

command-and-controlpayload-developmentpenetration-testing-frameworks+2
272 months ago
selenium-node-takeover-kit preview

selenium-node-takeover-kit

GitHubjonstratton/selenium-node-takeover-kit

A collection of selenium tests that might aid it takeover of a selenium node

command-and-controldata-exfiltrationexploit-frameworks+6
28 months ago
gitpwnd preview

gitpwnd

GitHubnccgroup/gitpwnd

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

command-and-controlpenetration-testingpersistence-mechanisms+3
1453 years ago
CVE-2025-64446-FortiWeb-CGI-Bypass-PoC preview

CVE-2025-64446-FortiWeb-CGI-Bypass-PoC

GitHubsxyrxyy/cve-2025-64446-fortiweb-cgi-bypass-poc
exploitationpenetration-testingred-teaming+3
139 months ago
relay_bible preview

relay_bible

GitHubrootsecdev/relay_bible

Technical Reference to multiple relay techniques

authenticationcurated-resourceseducation+8
1933 months ago
malicious-pdf preview

malicious-pdf

GitHubjonaslejon/malicious-pdf

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

data-exfiltrationeducationexploitation+6
4.1k2 months ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
63 months ago
reverse-shell preview

reverse-shell

GitHublukechilds/reverse-shell

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

command-and-controlexploitationpenetration-testing+3
2.1k6 months ago
BlueSAM preview

BlueSAM

GitHubincursi0n/bluesam

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

command-and-controlexploitationpayload-development+3
1674 months ago
foolav preview

foolav

GitHubhvqzao/foolav

Pentest tool for antivirus evasion and running arbitrary payload on target Wintel host

penetration-testingred-teaming
17310 years ago
Previous123Next