Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2448 results
PurpleSharp preview

PurpleSharp

GitHubmvelazc0/purplesharp

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

adversarial-attackeducationlateral-movement+4
848
6 months ago
WSC2 preview

WSC2

GitHubarno0x/wsc2

A WebSocket C2 Tool

command-and-controlexploitationpayload-generation+2
4338 years ago
PPLcontrol preview

PPLcontrol

GitHubitm4n/pplcontrol

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

defensive-toolsexploitationprivilege-escalation+1
4073 years ago
linset preview

linset

GitHubvk496/linset

Evil Twin Attack Bash script

educationphishingred-teaming+3
57712 years ago
CVE-2025-67511 preview

CVE-2025-67511

GitHubedoardottt/cve-2025-67511

Detailed disclosure of CVE-2025-67511, a command injection vulnerability in the CAI framework's SSH tool that allows AI agents to be tricked into…

ai-securitycommand-and-controleducation+5
63 months ago
PAKURI-THON preview

PAKURI-THON

GitHub01rabbit/pakuri-thon

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

command-and-controlexploit-frameworksinformation-gathering+7
284 years ago
WebDavC2 preview

WebDavC2

GitHubarno0x/webdavc2

A WebDAV PROPFIND C2 tool

command-and-controlpayload-generationpenetration-testing+1
1208 years ago
below-log-race-poc preview

below-log-race-poc

GitHubdanil-koltsov/below-log-race-poc

PoC for CVE-2025-27591 – Local privilege escalation in the below monitoring tool. By symlinking its log file to /etc/passwd, an attacker can inject a…

exploitationpenetration-testingpost-exploitation+3
11 year ago
DSCourier preview

DSCourier

GitHubdylandavis1/dscourier

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

configuration-auditingdefensive-toolspenetration-testing+3
2112 months ago
Remote-Desktop-Caching- preview

Remote-Desktop-Caching-

GitHubviralmaniar/remote-desktop-caching-

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

digital-forensicsforensicsincident-response+4
2188 years ago
shouganaiyo-loader preview

shouganaiyo-loader

GitHubnccgroup/shouganaiyo-loader

shouganaiyo-loader is a cross-platform Frida-based Node.js command-line tool that forces Java processes to load a Java/JVMTI agent regardless of…

exploitationids-ips-evasionpenetration-testing+2
394 years ago
poc-cve-2026-32255 preview

poc-cve-2026-32255

GitHubkoadt/poc-cve-2026-32255

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

educationexploitationpenetration-testing+3
26 months ago
PyRIT preview

PyRIT

GitHubmicrosoft/pyrit

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

adversarial-attackai-securitymachine-learning+2
4.5k18h 17m ago
KeePwn preview

KeePwn

GitHuborange-cyberdefense/keepwn

A python tool to automate KeePass discovery and secret extraction.

exploitationpassword-crackingpost-exploitation+1
5301 year ago
AutoRDPwn preview

AutoRDPwn

GitHubjoelgmsec/autordpwn

The Shadow Attack Framework

lateral-movementpassword-crackingpayload-generation+5
1.1k4 years ago
KrbRelayUp preview

KrbRelayUp

GitHubdec0ne/krbrelayup

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

authenticationexploitationimpersonation-tools+4
1.7k4 years ago
smbAutoRelay preview

smbAutoRelay

GitHubcheshireca7/smbautorelay

SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environments.

authenticationexploitationlateral-movement+2
465 years ago
CPLDCOMTrigger preview

CPLDCOMTrigger

GitHubklsecservices/cpldcomtrigger

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

exploitationlateral-movementpenetration-testing+2
488 months ago
Previous1…456…100Next