Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
skills preview

skills

GitHubspecterops/skills

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

command-and-controleducationexploitation+9
671
3 days ago
web3-decoder preview

web3-decoder

GitHubuwctcjnwlk/web3-decoder

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

api-securitypenetration-testingreverse-engineering+2
2166 days ago
speakeasy preview

speakeasy

GitHubmandiant/speakeasy

Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled runtime, emulating APIs, process/thread behavior,…

binary-analysisdynamic-analysis-sandboxingmalware-analysis+1
2.1k11 days ago
DeepZero preview

DeepZero

GitHub416rehman/deepzero

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows…

ai-assisted-reversingbinary-analysisfuzzing+3
72917 days ago
firmware-reverse-engineering preview

firmware-reverse-engineering

GitHuborbitcurve/firmware-reverse-engineering

Agent skills for firmware extraction, static analysis, Ghidra reverse engineering, emulation, and security reporting, packaged for Claude Code and…

binary-analysiscurated-resourcesdynamic-analysis-sandboxing+5
19019 days ago
auto_extract_offsets preview

auto_extract_offsets

GitHubctn-qvo/auto_extract_offsets

Automated offset calculator for CVE-2026-43499, enabling precise memory offset computation for vulnerability exploitation and binary analysis.

binary-analysisexploitationpenetration-testing+2
132 months ago
CVE-2026-9490 preview

CVE-2026-9490

GitHubugvxb/cve-2026-9490

The ACCSvc service creates a Named Pipe with a weak Security Descriptor that allows any authenticated user to connect and send messages. When a…

binary-analysisexploitationpenetration-testing+3
3 months ago
shootback preview

shootback

GitHubaploium/shootback

a reverse TCP tunnel let you access target behind NAT or firewall

network-securitypenetration-testingred-teaming+1
9765 months ago
OpenShell preview

OpenShell

GitHubiss4cf0ng/openshell

Lightweight Go-based reverse shell management server with a web GUI for interactive shell sessions, session management, and multi-tab terminal…

command-and-controlpenetration-testingred-teaming+3
266 months ago
CVE-2024-11467 preview

CVE-2024-11467

GitHubnull-event/cve-2024-11467

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

binary-exploitationcode-analysisexploitation+4
8 months ago
TopazTerminator preview

TopazTerminator

GitHubthannikudam/topazterminator

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…

binary-exploitationdefensive-toolsexploitation+5
1428 months ago
CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit preview

CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit

GitHubpl4tyz/cve-2025-14611-centrestack-and-triofox-full-poc-exploit

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

authenticationcryptographyexploitation+6
9 months ago
CVE-2025-51726 preview

CVE-2025-51726

GitHubmeisterlos/cve-2025-51726

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

binary-exploitationexploitationmalware-analysis+4
1 year ago
CVE-2025-26244 preview

CVE-2025-26244

GitHubjarm222/cve-2025-26244

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

command-and-controlexploitationpayload-development+4
1 year ago
xepor preview

xepor

GitHubxepor/xepor

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

penetration-testingphishing-toolsred-teaming+3
2151 year ago
RpcInvestigator preview

RpcInvestigator

GitHubtrailofbits/rpcinvestigator

Windows RPC interface discovery and analysis tool with visual endpoint enumeration, PE parsing, symbol resolution, real-time ETW sniffing, and…

binary-analysispenetration-testingreverse-engineering+1
3652 years ago
detaped preview

detaped

GitHubnccgroup/detaped

Detaped is a Python disassembler and decompiler for Duktape. The intended use is for source code review and analysis in situations where you only…

binary-analysiscode-analysispenetration-testing+2
33 years ago
super-xray preview
Archived

super-xray

GitHub4ra1n/super-xray

Web漏洞扫描工具XRAY的GUI启动器

exploitationpenetration-testingreverse-engineering+3
1.3k3 years ago
Previous12Next