Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
frp preview

frp

GitHubfatedier/frp

A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.

network-securitypenetration-testingred-teaming+1
109.8k12h 34m ago
wa-tunnel preview

wa-tunnel

GitHubaleixrodriala/wa-tunnel

Tunneling Internet traffic over Whatsapp

educationnetwork-securityred-teaming
3.3k3 years ago
CatSniffer preview

CatSniffer

GitHubelectroniccats/catsniffer

CatSniffer is an original multiprotocol and multiband board for sniffing, communicating, and attacking IoT (Internet of Things) devices using the…

bluetooth-securityeducationhardware-iot-security+7
95310 months ago
SharpWeb preview

SharpWeb

GitHubdjhohnstein/sharpweb

.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.

information-gatheringpassword-crackingpost-exploitation+1
5428 years ago
LARE preview

LARE

GitHubm4lv0id/lare

[L]ocal [A]uto [R]oot [E]xploiter is a simple bash script that helps you deploy local root exploits from your attacking machine when your victim…

exploitationpenetration-testingprivilege-escalation+1
679 years ago
ComoDoS preview

ComoDoS

GitHubmalwaretech/comodos

A remote denial-of-service zero day vulnerability in Comodo Internet Security firewall

exploitationexploit-frameworkspenetration-testing+2
134 months ago
bepr preview

bepr

GitHubaperocky/bepr

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

authenticationcommand-and-controlpenetration-testing+3
4 months ago
CVE-2025-29017 preview

CVE-2025-29017

GitHubb1tm4r/cve-2025-29017

Proof-of-concept exploit for CVE-2025-29017, demonstrating remote code execution via malicious file upload in Code Astro Internet Banking System…

exploitationpayload-generationpenetration-testing+3
11 year ago
-CVE-2017-7494-Samba-Exploit-POC preview

-CVE-2017-7494-Samba-Exploit-POC

GitHubadjaliya/-cve-2017-7494-samba-exploit-poc

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable…

exploitationpenetration-testingred-teaming+3
5 years ago
awesome-osint-arsenal preview

awesome-osint-arsenal

GitHubrawfilejson/awesome-osint-arsenal

OSINT & recon toolkit // 100+ tools, one-command installer, SOCMINT, GEOINT, network recon, dark web, forensics & more.

ctfcurated-resourcesdigital-forensics+8
3.2k1 month ago
aimap preview

aimap

GitHubbishopfox/aimap

Discover Exposed AI Services

ai-securityinformation-gatheringosint+6
4315 months ago
XFLTReaT preview

XFLTReaT

GitHubearthquake/xfltreat

XFLTReaT tunnelling framework

data-exfiltrationnetwork-securitypenetration-testing+1
3316 years ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5621 days ago
Neton preview

Neton

GitHubaetsu/neton

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

educationinformation-gatheringmalware-analysis+1
993 years ago
IIS-Backdoor preview

IIS-Backdoor

GitHubnu11secur1ty/iis-backdoor

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

command-and-controlexploitationids-ips-evasion+4
346 years ago
CVE-2018-15982 preview

CVE-2018-15982

GitHubscanfsec/cve-2018-15982

Aggressor Script to launch IE driveby for CVE-2018-15982.

command-and-controlexploitationpayload-generation+3
296 years ago
phantom-brain preview

phantom-brain

GitHubottoyrocky/phantom-brain

Red portatil de reconocimiento inteligente con IA offline

ai-securityeducationexploitation+9
164 months ago
rosemary preview

rosemary

GitHubblue0x1/rosemary

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

command-and-controldns-analysislateral-movement+4
142 months ago
Previous12Next