Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
WhoamiAlternatives preview

WhoamiAlternatives

GitHubricardojoserf/whoamialternatives

Different methods to get current username without using whoami

information-gatheringmalware-analysispost-exploitation+2
187
2 years ago
profilehound preview

profilehound

GitHubm4lwhere/profilehound

ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets by…

information-gatheringlateral-movementosint+4
1644 months ago
clroxide preview

clroxide

GitHubyamakadi/clroxide

A rust library that allows you to host the CLR and execute dotnet binaries.

payload-developmentpost-exploitationred-teaming
2351 year ago
UnCanny preview

UnCanny

GitHub0xhossam/uncanny

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

educationexploitationlateral-movement+4
883 months ago
rusty_joomla_rce preview

rusty_joomla_rce

GitHubkiks7/rusty_joomla_rce

Rusty Joomla RCE Exploit

exploitationpenetration-testingred-teaming+2
683 years ago
CVE-2026-34159 preview

CVE-2026-34159

GitHubcasp3r0x0/cve-2026-34159

0 Click RCE exploit for CVE-2026-34159 Lama.cpp RPC server

exploitationpayload-developmentpenetration-testing+3
285 months ago
apfell-chrome-extension-c2server preview

apfell-chrome-extension-c2server

GitHubxorrior/apfell-chrome-extension-c2server

Apfell C2 Server for the Google Chrome Extension Payload

command-and-controlexploit-frameworkspayload-development+3
126 years ago
njutils preview

njutils

GitHubseep1959/njutils

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

command-and-controlpayload-developmentpenetration-testing+3
78 years ago
cve-2026-27483 preview

cve-2026-27483

GitHubthewhiteh4t/cve-2026-27483

MindsDB Path Traversal to RCE PoC

exploitationpayload-developmentpenetration-testing+3
56 months ago
spb preview

spb

GitHubiknowjason/spb

Scripts for testing Shortest Path Bridging (SPB-Mac) vulnerabilities, including CVE-2016-2783 enumeration on Avaya VOSS Ethernet switches during…

exploitationnetwork-securitypenetration-testing+3
27 years ago
CVE-2022-37706-SUID preview

CVE-2022-37706-SUID

GitHubtactical-hack/cve-2022-37706-suid

CVE-2022-37706-Enlightenment v0.25.3 - Privilege escalation

binary-exploitationexploitationpenetration-testing+3
2 years ago
no-defender preview
Archived

no-defender

GitHubes3n1n/no-defender

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

adversarial-attackids-ips-evasionpenetration-testing+3
2.0k2 years ago
Cloudmare preview
Archived

Cloudmare

GitHubmrh0wl/cloudmare

Cloudflare, Sucuri, Incapsula real IP tracker.

dns-analysisinformation-gatheringpenetration-testing+3
1.8k3 years ago
nanodump preview

nanodump

GitHubfortra/nanodump

The swiss army knife of LSASS dumping

exploitationmemory-forensicspayload-development+4
2.1k2 years ago
inception preview

inception

GitHubcarmaa/inception

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

digital-forensicsexploitationhardware-security+6
1.6k1 year ago
OffensiveDLR preview

OffensiveDLR

GitHubbyt3bl33d3r/offensivedlr

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

code-analysiscommand-and-controldynamic-code-analysis+9
5255 years ago
NativeDump preview

NativeDump

GitHubricardojoserf/nativedump

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

memory-forensicspost-exploitationred-teaming
7501 month ago
agentic-radar preview

agentic-radar

GitHubsplx-ai/agentic-radar

A security scanner for your LLM agentic workflows

adversarial-attackai-securitydevsecops+5
1.1k10 months ago
Previous1234567Next