Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
Starlink-FI preview

Starlink-FI

GitHubkuleuven-cosic/starlink-fi

Voltage fault-injection modchip for black-box security evaluation of Starlink terminals, bypassing bootloader signature verification to execute…

binary-analysisembedded-systems-securityexploitation+4
1.0k
3 years ago
dns-black-cat preview

dns-black-cat

GitHubzux0x3a/dns-black-cat

Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

command-and-controldata-exfiltrationdns-analysis+3
1123 years ago
cisco_asa_research preview

cisco_asa_research

GitHubjbaines-r7/cisco_asa_research

Cisco ASA Software and ASDM Security Research

exploitationexploit-frameworksinformation-gathering+7
873 years ago
CVE-2022-39196- preview

CVE-2022-39196-

GitHubdayiliwaseem/cve-2022-39196-

Black board CMS Escalation of Privileges

data-exfiltrationexploitationinformation-gathering+3
3 years ago
Blackhat-USA-2022-Materials preview

Blackhat-USA-2022-Materials

GitHubh4wkst3r/blackhat-usa-2022-materials

Presentation materials for my Black Hat USA 2022 Briefing and Arsenal talks

curated-resourceseducationexploitation+3
644 years ago
napper-for-tpm preview

napper-for-tpm

GitHubkkamagui/napper-for-tpm

TPM vulnerability checking tool for CVE-2018-6622. This tool will be published at Black Hat Asia 2019 and Black Hat Europe 2019

embedded-systems-securityexploitationfirmware-analysis+3
1074 years ago
black-widow preview

black-widow

GitHuboffensive-hub/black-widow

GUI based offensive penetration testing tool (Open Source)

crawlerinformation-gatheringpacket-sniffing-analysis+2
2234 years ago
CVE-2018-17553 preview

CVE-2018-17553

GitHubmidwinterstomb/cve-2018-17553

CVE-2018-17553 PoC

exploitationpayload-generationpenetration-testing+2
4 years ago
m3 preview

m3

GitHubthisislibra/m3

A simple and scalable Android bot emulation framework, as presented at Black Hat Europe 2021's Arsenal, as well as atHack 2021's Arsenal

android-securityeducationmalware-analysis+1
294 years ago
BlackMamba preview
Archived

BlackMamba

GitHubloseys/blackmamba

C2/post-exploitation framework

command-and-controldata-exfiltrationencryption-decryption-tools+5
1.2k5 years ago
AFL preview
Archived

AFL

GitHubgoogle/afl

american fuzzy lop - a security-oriented fuzzer

binary-analysisfuzzingpenetration-testing+1
4.2k5 years ago
autoresponder preview

autoresponder

GitHublawiet47/autoresponder

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…

forensicsincident-response
565 years ago
xsser preview

xsser

GitHubvarbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

exploitationpayload-developmentpenetration-testing+3
4236 years ago
swapgs-attack-poc preview

swapgs-attack-poc

GitHubbitdefender/swapgs-attack-poc

This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)

binary-exploitationeducationexploitation+2
416 years ago
drAFL preview

drAFL

GitHubmxmssh/drafl

AFL + DynamoRIO = fuzzing binaries with no source code on Linux

binary-analysisdynamic-analysis-sandboxingexploitation+1
2496 years ago
vbscan preview
Archived

vbscan

GitHubowasp/vbscan

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

exploitationinformation-gatheringpenetration-testing+3
3267 years ago
4062-1 preview

4062-1

GitHubngyanch/4062-1

CVE-2008-0128

code-analysisdevsecopssupply-chain-security+1
7 years ago
joomlavs preview
Archived

joomlavs

GitHubrastating/joomlavs

A black box, Ruby powered, Joomla vulnerability scanner

information-gatheringpenetration-testingreconnaissance+3
2748 years ago
Previous1234Next