Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2447 results
DLLirant preview
Archived

DLLirant

GitHubsh0ckfr/dllirant

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

binary-analysisexploitationprivilege-escalation+2
322
3 years ago
AutoSploit preview

AutoSploit

GitHubnullarray/autosploit

Automated Mass Exploiter

command-and-controlexploit-frameworksinformation-gathering+5
5.3k6 years ago
SharpEDRChecker preview

SharpEDRChecker

GitHubpwndexter/sharpedrchecker

C# tool that enumerates running processes, loaded DLLs, installed services, and drivers to detect the presence of AV, EDR, and logging products,…

defensive-toolsinformation-gatheringpenetration-testing+2
7566 months ago
Jasmin-Ransomware preview

Jasmin-Ransomware

GitHubcodesiddhant/jasmin-ransomware

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

command-and-controlencryption-decryption-toolsexploitation+5
2875 years ago
BigBountyRecon preview

BigBountyRecon

GitHubviralmaniar/bigbountyrecon

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial…

dns-subdomain-enumerationeducationinformation-gathering+6
1.6k5 years ago
shellerator preview

shellerator

GitHubshutdownrepo/shellerator

Simple CLI tool for the generation of bind and reverse shells in multiple languages

payload-generationpenetration-testingred-teaming+1
3943 months ago
SharpToken preview

SharpToken

GitHubbeichendream/sharptoken

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

lateral-movementpost-exploitationprivilege-escalation+1
4952 years ago
ShadowSpray preview

ShadowSpray

GitHubdec0ne/shadowspray

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the…

authenticationexploitationpenetration-testing+3
4933 years ago
Auto-Elevate preview

Auto-Elevate

GitHubfullshade/auto-elevate

Escalate from a low-integrity Administrator account to NT AUTHORITY\SYSTEM without an LPE exploit by combining a COM UAC bypass and Token…

exploitationpenetration-testingprivilege-escalation+1
1614 years ago
CLR-Unhook preview

CLR-Unhook

GitHubhwbp/clr-unhook

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

defensive-toolsexploitationpayload-development+3
2179 months ago
CVE-2023-41425-RCE-WonderCMS-4.3.2 preview

CVE-2023-41425-RCE-WonderCMS-4.3.2

GitHubtea-on/cve-2023-41425-rce-wondercms-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

educationexploitationpayload-generation+5
81 year ago
detection-validation preview

detection-validation

GitHubalwashali/detection-validation

Detection rule validation

adversarial-attackdefensive-toolsintrusion-detection+1
422 years ago
macro_pack preview
Archived

macro_pack

GitHubsevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exploit-frameworkslateral-movementpayload-generation+6
2.3k2 years ago
HandleKatz preview

HandleKatz

GitHubcodewhitesec/handlekatz

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

defensive-toolsmemory-forensicspayload-generation+3
5983 years ago
EXOCET-AV-Evasion preview

EXOCET-AV-Evasion

GitHubtanc7/exocet-av-evasion

EXOCET - AV-evading, undetectable, payload delivery tool

command-and-controlcryptographyeducation+9
8384 years ago
Nac_Bypass_Agent preview

Nac_Bypass_Agent

GitHubalperenugurlu/nac_bypass_agent

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

educationids-ips-evasionimpersonation-tools+5
733 years ago
Multi-threaded-mass-exploiter-CVE-2018-13379-POC preview

Multi-threaded-mass-exploiter-CVE-2018-13379-POC

GitHubinstructor-admin/multi-threaded-mass-exploiter-cve-2018-13379-poc

CVE-2018-13379 mass exploiter for Fortinet FortiOS SSL VPN. Extracts credentials instantly, saves to CSV + PostgreSQL. Multi-threaded, no bullshit…

exploitationinformation-gatheringpassword-attacks+4
13 months ago
kickthemout preview

kickthemout

GitHubk4m4/kickthemout

💤 Kick devices off your network by performing an ARP Spoof attack.

educationnetwork-securitypenetration-testing+1
2.7k6 years ago
Previous1234…100Next