Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
mikrotik-beast preview

mikrotik-beast

GitHubmahmoodsabir/mikrotik-beast

Mass MikroTik WinBox Exploitation tool, CVE-2018-14847

exploitationinformation-gatheringnetwork-security+3
67 years ago
Crashcast-Exploit preview

Crashcast-Exploit

GitHub649/crashcast-exploit

This tool allows you mass play any YouTube video, terminate apps and rename Chromecast device(s) obtained from Shodan.io

exploitationinformation-gatheringiot-security+1
1657 years ago
ADCSDevilCOM preview

ADCSDevilCOM

GitHub7hepr0fess0r/adcsdevilcom

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

authentication-authorizationexploitationpayload-generation+5
16711 months ago
Nim-Reverse-Shell preview

Nim-Reverse-Shell

GitHubsn1r/nim-reverse-shell

A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell…

educationpayload-developmentpayload-generation+1
1253 years ago
Memcrashed-DDoS-Exploit preview

Memcrashed-DDoS-Exploit

GitHub649/memcrashed-ddos-exploit

DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API

exploitationinformation-gatheringosint
1.4k7 years ago
heartbleed-masstest preview

heartbleed-masstest

GitHubmusalbas/heartbleed-masstest

Multi-threaded tool for scanning many hosts for CVE-2014-0160.

information-gatheringnetwork-securitypenetration-testing+3
57111 years ago
Ghost-In-The-Logs preview

Ghost-In-The-Logs

GitHubbats3c/ghost-in-the-logs

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

defensive-toolsids-ips-evasionprivilege-escalation
6246 years ago
PPLcontrol preview

PPLcontrol

GitHubitm4n/pplcontrol

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

defensive-toolsexploitationprivilege-escalation+1
4073 years ago
java-remote-class-loader preview

java-remote-class-loader

GitHubjoaovarelas/java-remote-class-loader

Client-server tool for remotely loading and executing Java bytecode via ClassLoader and Reflect API, with ChaCha20 encryption and keepalive…

command-and-controlencryption-decryption-toolsexploitation+3
344 years ago
susinternals preview

susinternals

GitHubsensepost/susinternals

psexecsvc - a python implementation of PSExec's native service implementation

authenticationlateral-movementpenetration-testing+3
3146 months ago
MalSCCM preview

MalSCCM

GitHubnettitude/malsccm

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

exploitationlateral-movementpenetration-testing+1
2564 years ago
Kitsune preview

Kitsune

GitHubjoelgmsec/kitsune

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

command-and-controlexploit-frameworkspayload-generation+2
1051 year ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

educationexploitationlabs-practice+3
22 years ago
BlueDucky preview

BlueDucky

GitHubsergeb250/blueducky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The…

bluetooth-securityexploitationpayload-generation+3
21 year ago
CVE-2023-23397-Patch preview

CVE-2023-23397-Patch

GitHubzeppperoni/cve-2023-23397-patch

CVE-2023-23397 powershell patch script for Windows 10 and 11

scripting-automationvulnerability-analysis
3 years ago