Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
39
13 days ago
pickl3 preview
Archived

pickl3

GitHubhlldz/pickl3

Windows active user credential phishing tool

payload-generationpenetration-testingphishing+2
2846 years ago
Fudge preview

Fudge

GitHubdale-ruane/fudge

Hiding implants in HTML files

payload-generationphishingred-teaming+1
646 years ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.9k4 months ago
Camelishing preview

Camelishing

GitHubazizaltuntas/camelishing

Social Engineering Tool

email-harvestingpayload-generationphishing+1
1898 years ago
pegasus-neo preview

pegasus-neo

GitHubsobri3195/pegasus-neo

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

exploitationforensicsosint+9
1287 months ago
evil-winrar preview

evil-winrar

GitHubyoumulijiang/evil-winrar

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)

exploitationpayload-generationphishing-tools+3
112 years ago
ImgBackdoor preview

ImgBackdoor

GitHubtsuyoken/imgbackdoor

Hide your payload into .jpg file

command-and-controlexploitationpayload-development+3
3944 years ago
poc-CVE-2026-64638- preview

poc-CVE-2026-64638-

GitHubmohwahyudi/poc-cve-2026-64638-

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

exploitationpayload-generationpenetration-testing+5
1 month ago
ChromeAlone preview

ChromeAlone

GitHubpraetorian-inc/chromealone

A tool to transform Chromium browsers into a C2 Implant

command-and-controlpayload-developmentpersistence-mechanisms+6
60411 months ago
GitBackdorizer preview

GitBackdorizer

GitHubunkl4b/gitbackdorizer

GitBackdorizer (bad name, I know!) Is a proof of concept from Ulisses Castro's talk - 50 ton of backdoors…

payload-developmentpenetration-testingred-teaming+1
518 years ago
xll_windows_reverse_shell preview

xll_windows_reverse_shell

GitHubh3x0v3rl0rd/xll_windows_reverse_shell

xll windows reverse shell

command-and-controlexploitationpayload-development+4
1 year ago
CVE-2021-28079 preview

CVE-2021-28079

GitHubg33xter/cve-2021-28079

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

command-and-controlexploitationpayload-development+3
44 years ago
CVE-2023-52076-PoC preview

CVE-2023-52076-PoC

GitHubgroppoxx/cve-2023-52076-poc

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

binary-exploitationexploitationpayload-generation+3
32 months ago
EmbedInHTML preview

EmbedInHTML

GitHubarno0x/embedinhtml

Embed and hide any file in an HTML file

payload-generationphishing-toolssocial-engineering+1
4899 years ago
WhatsRCE preview

WhatsRCE

GitHubkeepwannabe/whatsrce

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

exploitationmobile-securitypayload-generation+3
775 years ago
bash-bunny-payloads preview

bash-bunny-payloads

GitHubrxerium/bash-bunny-payloads

Personally crafted Bash Bunny Payloads

exploitationhardware-hackingpayload-development+2
21 year ago
CVE-2021-24884 preview

CVE-2021-24884

GitHubs1lkys/cve-2021-24884

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

exploitationpayload-developmentphishing-tools+3
14 years ago
Previous12Next