Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
94 results
CVE-2025-67887 preview

CVE-2025-67887

GitHubcyberok-org/cve-2025-67887

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…

code-analysiseducationexploitation+3
9 months ago
TeleShadow2 preview

TeleShadow2

GitHubparsingteam/teleshadow2

TeleShadow - Telegram Desktop Session Stealer (Windows)

malware-analysisremote-access-trojan
1178 years ago
TeleShadow3 preview

TeleShadow3

GitHubeternalc0der/teleshadow3

Telegram Desktop Session Stealer

information-gatheringmalware-analysisremote-access-trojan+1
1837 years ago
Samuraizer preview

Samuraizer

GitHubzomry1/samuraizer

NotebookLM on steroids — purpose-built for security researchers.

crawlercurated-resourceseducation+5
296 months ago
lanGhost preview
Archived

lanGhost

GitHubxdavidhu/langhost

👻 A LAN dropbox chatbot controllable via Telegram

command-and-controleducationinformation-gathering+8
3526 years ago
TurkoRat preview

TurkoRat

GitHubcryst4linqq/turkorat

Fully undetected grabber (grabs wallets, passwords, cookies, modifies discord client etc.)

anti-botdata-exfiltrationinformation-gathering+5
1843 years ago
gOSINT preview

gOSINT

GitHubnhoya/gosint

OSINT Swiss Army Knife

crawlerdns-subdomain-enumerationemail-harvesting+6
6757 years ago
DarkTortilla-RAT-Telegram-Exfiltration-Payload-Extraction-Analysis preview

DarkTortilla-RAT-Telegram-Exfiltration-Payload-Extraction-Analysis

GitHubkaandemir993/darktortilla-rat-telegram-exfiltration-payload-extraction-analysis

Reverse engineering analysis of DarkTortilla RAT, a sophisticated malware that steals credit card data, decrypts browser passwords, and exfiltrates…

command-and-controldata-exfiltrationdigital-forensics+4
471 month ago
malvinci preview

malvinci

GitHubgsoffmarket/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controldata-exfiltrationpayload-development+3
592 years ago
submonitor preview

submonitor

GitHubxpl0ited1/submonitor

Subdomain monitor with reporting capabilities to Slack, Discord and Telegram

dns-subdomain-enumerationinformation-gatheringosint+2
143 years ago
zeekjs-notice-telegram preview

zeekjs-notice-telegram

GitHubcorelight/zeekjs-notice-telegram

Zeek Notice Telegram (ZeekJS edition)

defensive-toolsincident-responseintrusion-detection
33 years ago
CVE-2025-51396 preview

CVE-2025-51396

GitHubthewhiteevil/cve-2025-51396

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

exploitationinformation-gatheringpenetration-testing+3
11 year ago
ARTLAS preview

ARTLAS

GitHubmthbernardes/artlas

Apache Real Time Logs Analyzer System

incident-responseintrusion-detectionlog-analysis+3
1265 years ago
Win10Pcap-Exploit preview

Win10Pcap-Exploit

GitHubrootkitsmm-zz/win10pcap-exploit

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )

binary-exploitationexploitationpost-exploitation+2
6110 years ago
polymaster preview

polymaster

GitHubneur0map/polymaster

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

anomaly-detectioncrawlerdata-exfiltration+3
2727 days ago
XSSFire preview

XSSFire

GitHubseifelsallamy/xssfire

A standalone Blind XSS Script.

data-exfiltrationexploitationinformation-gathering+3
471 year ago
CVE-2025-11749 preview

CVE-2025-11749

GitHubnxploited/cve-2025-11749

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

exploitationinformation-gatheringpenetration-testing+4
811 months ago
CVE-2017-7679 preview

CVE-2017-7679

GitHubal-lord0x/cve-2017-7679

CVE-2017-7679 POC SCRIPT BY LORDWARE....

exploitationpayload-generationpenetration-testing+2
111 months ago
Previous123456Next