Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
633 results
R2Socks preview

R2Socks

GitHubivancabrera02/r2socks

SOCKS5 proxy tunneled through Cloudflare R2 object storage, with Python and dependency-free C++ agents relaying TCP traffic via encrypted R2 objects…

command-and-controldata-exfiltrationencryption-decryption-tools+5
31
17 days ago
waybend preview

waybend

GitHubprinciplebreach/waybend

Self-hosted SSRF redirect, payload, callback, and DNS workbench

command-and-controldns-analysisinformation-gathering+9
513 days ago
Darkcloak preview

Darkcloak

GitHub0x574r/darkcloak

Linux process identity cloaking tool that spoofs comm, argv, cmdline, environ, exe path, and VMAs via an 11-phase prctl pipeline to impersonate…

binary-analysisfingerprint-spoofingids-ips-evasion+6
113 months ago
flipper-mcp preview

flipper-mcp

GitHubroostercoopllc/flipper-mcp

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.

ai-securitybluetooth-securitycommand-and-control+9
226 months ago
security-portfolio preview

security-portfolio

GitHubmitsu-bis/security-portfolio

Security portfolio of original responsible-disclosure findings, CTF and lab write-ups, methodology notes, and purpose-built pentest tooling covering…

ctfcurated-resourceseducation+6
4 days ago
DROS-VEP-lite preview

DROS-VEP-lite

GitHubtop-celestial-company-ltd/dros-vep-lite

Open-source, 100% reproducible AI Agent Runtime Security Benchmark & Sandbox Environment (RFC-010 Draft Protocol).

ai-securitydefensive-toolsdynamic-analysis-sandboxing+8
113 days ago
gopacket preview

gopacket

GitHubmandiant/gopacket

A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

command-and-controlexploit-frameworkslateral-movement+7
7071 month ago
blackarch preview

blackarch

GitHubblackarch/blackarch

An ArchLinux based distribution for penetration testers and security researchers.

curated-resourceseducationexploit-frameworks+8
3.5k5 days ago
LOLRMM preview

LOLRMM

GitHubmagicsword-io/lolrmm

Curated catalog of Remote Monitoring and Management tools abused by threat actors, with YAML profiles, Sigma detection rules, and API access for…

curated-resourcesdefensive-toolseducation+6
3964 days ago
cve-2026-28576 preview

cve-2026-28576

GitHubaayushbankar/cve-2026-28576

PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…

android-securitydata-exfiltrationexploitation+6
4 days ago
CVE-2026-41089-Netlogon-RCE-PoC preview

CVE-2026-41089-Netlogon-RCE-PoC

GitHubgillarchnganasan2735/cve-2026-41089-netlogon-rce-poc

Automate Netlogon CVE-2026-41089 validation and defensive testing through integrated AI security workflows, enabling rapid risk assessment and…

defensive-toolseducationexploitation+5
4 days ago
adnullenum preview

adnullenum

GitHubcrypt0p3g/adnullenum

One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.

defensive-toolsinformation-gatheringnetwork-security+5
378 days ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
187 days ago
ZX-DDoS preview

ZX-DDoS

GitHubmrgoofydev/zx-ddos

Python-based DDoS stress testing tool for educational and authorized network security evaluation, supporting configurable workers and request counts.

educationgeneral-purpose-utilitiesnetwork-security+3
516 days ago
red-teaming-auto-mode preview

red-teaming-auto-mode

GitHubsafety-research/red-teaming-auto-mode

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

ai-securityeducationfuzzing+3
11 day ago
MS09-050 preview

MS09-050

GitHubbytejmp/ms09-050

Python exploit for MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow, with vulnerability scanner, arch auto-detection, and x86/x64 reverse…

exploitationinformation-gatheringnetwork-security+7
8 days ago
CVE-2026-44840-poc preview

CVE-2026-44840-poc

GitHubisaca0315/cve-2026-44840-poc

Docker lab reproducing CVE-2026-44840, a DQL injection in Dgraph's checkUserPassword GraphQL query, with exploit script and vulnerable vs patched…

database-securityexploitationlabs-practice+5
9 days ago
F31 preview

F31

GitHubgmh5225/f31

Tool for hiding Kali Linux on the network

anti-botdefensive-toolsfingerprint-spoofing+6
32 years ago
Previous12…36Next