Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
115 results
mkdev preview

mkdev

GitHubvenkatkrishna07/mkdev

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

dns-analysisencryption-decryption-toolsnetwork-security+3
141
2 months ago
sccm-http-looter preview

sccm-http-looter

GitHubbadsectorlabs/sccm-http-looter

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

data-exfiltrationinformation-gatheringmisconfiguration+3
2161 year ago
Reverse_HTTPS_Bot preview

Reverse_HTTPS_Bot

GitHubahhh/reverse_https_bot

A python based https remote access trojan for penetration testing

command-and-controlpayload-developmentpenetration-testing+3
8410 years ago
zoshrinkC2 preview

zoshrinkC2

GitHubdemon-i386/zoshrinkc2

DNS over HTTPS targeted malware (only runs once)

command-and-controlcryptographyids-ips-evasion+3
973 years ago
PULSE-C2 preview

PULSE-C2

GitHub28zaaky/pulse-c2

HTTPS C&C Framework with encrypted beacons, web dashboard, and Windows agent.

command-and-controlencryption-decryption-toolspayload-development+2
536 months ago
Sleight preview

Sleight

GitHubv1v1/sleight

Empire HTTP(S) C2 redirector setup script

command-and-controlids-ips-evasionpenetration-testing+2
488 years ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
376 years ago
qu1ckdr0p2 preview

qu1ckdr0p2

GitHubbyinarie/qu1ckdr0p2

Quicky serve files over http or https using flask.

payload-developmentpayload-generationpenetration-testing+3
352 years ago
CVE-2025-25198-PoC preview

CVE-2025-25198-PoC

GitHubgroppoxx/cve-2025-25198-poc

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

exploitationpassword-attackspenetration-testing+3
203 months ago
Log4j-Vulnerability preview

Log4j-Vulnerability

GitHubdemining/log4j-vulnerability

Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can…

educationexploitationioc-management+3
63 years ago
CVE-2025-64446 preview

CVE-2025-64446

GitHubverylazytech/cve-2025-64446

CVE-2025-64446 - A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0…

ctfeducationexploitation+3
39 months ago
CVE-2023-3452---WordPress-Canto-Plugin-RCE preview

CVE-2023-3452---WordPress-Canto-Plugin-RCE

GitHubalpastx/cve-2023-3452---wordpress-canto-plugin-rce

CVE-2023-3452 exploit for WordPress Canto plugin RCE, HTTPS support included

exploitationpayload-generationpenetration-testing+3
5 months ago
CVE-2012-1823-exploit-for-https-user-password-web preview

CVE-2012-1823-exploit-for-https-user-password-web

GitHubdmitri131313/cve-2012-1823-exploit-for-https-user-password-web

CVE-2012-1823 exploit for https user password website.

exploitationinformation-gatheringpenetration-testing+2
11 year ago
vuln-CVE-2022-41082 preview

vuln-CVE-2022-41082

GitHubnotareaperbutdr34p3r/vuln-cve-2022-41082

https & http

exploitationnetwork-securitypenetration-testing+3
3 years ago
httptoolkit preview

httptoolkit

GitHubhttptoolkit/httptoolkit

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac 🎉 Open an issue here to…

api-security-testinggeneral-purpose-utilitiespenetration-testing+1
3.6k6 months ago
frida-interception-and-unpinning preview

frida-interception-and-unpinning

GitHubhttptoolkit/frida-interception-and-unpinning

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

android-securityios-securitymobile-app-pentesting+4
2.3k3 days ago
martian preview
Archived

martian

GitHubgoogle/martian

Martian is a library for building custom HTTP/S proxies

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
2.0k1 year ago
ip-https-tools preview
Archived

ip-https-tools

GitHubtakeshixx/ip-https-tools

Tools for the IP over HTTPS (IP-HTTPS) Tunneling Protocol

dns-analysisnetwork-mappingnetwork-security+3
911 years ago
Previous1234567Next