Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Data Exfiltration

Tools for extracting sensitive data from compromised systems without detection.

NewestRelevanceMost popularRecently updated
649 results
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

privilege-escalationmemory-forensicspersistence-mechanisms+6
1
1 day ago
iron-proxy preview

iron-proxy

GitHubparadigmxyz/iron-proxy

An egress firewall for untrusted workloads.

container-securityweb-proxies-interceptiondata-exfiltration+5
6125 days ago
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

persistence-mechanismsdata-exfiltrationpost-exploitation+5
2 days ago
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability preview

CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability

GitHubgraysignal/cve-2024-23897-jenkins-arbitrary-read-file-vulnerability

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

vulnerability-analysisexploitationweb-application-exploitation+4
32 years ago
CVE-2026-74251 preview

CVE-2026-74251

GitHubtoanln-cov/cve-2026-74251

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

vulnerability-analysisexploitationweb-application-exploitation+3
3 days ago
CVE-2026-26980 preview

CVE-2026-26980

GitHubvognik/cve-2026-26980

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

vulnerability-analysisexploitationweb-application-exploitation+4
104 days ago
SkeletonKey preview

SkeletonKey

GitHubdefineid/skeletonkey

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox

vulnerability-analysisexploitationdata-exfiltration+3
3 days ago
flar3ad preview

flar3ad

GitHubdaemoncibsec/flar3ad

POC of CVE-2026-51031 for arbitrary local file read

vulnerability-analysisexploitationweb-application-exploitation+2
4 days ago
CVE-2023-22047-Oracle-PeopleSoft-LFI preview

CVE-2023-22047-Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047-oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis preview

RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis

GitHubkaandemir993/redline-stealer-c2-defender-bypass-payload-analysis

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

memory-forensicspersistence-mechanismsreverse-engineering+4
16 days ago
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

vulnerability-analysisexploitationweb-application-exploitation+6
6 days ago
keepass-exfil-forensics preview

keepass-exfil-forensics

GitHubpugazhendii22/keepass-exfil-forensics

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

packet-sniffing-analysispassword-crackingmemory-forensics+6
6 days ago
CVE-2026-72550-poc preview

CVE-2026-72550-poc

GitHubabdugafforov-bobur/cve-2026-72550-poc

CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis preview

Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis

GitHubkaandemir993/agent-tesla-apc-injection-token-manipulation-registry-persistence-analysis

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

privilege-escalationpersistence-mechanismsreverse-engineering+4
313 days ago
CVE-2024-52806-PoC preview

CVE-2024-52806-PoC

GitHubheartlesseorg-dot/cve-2024-52806-poc
vulnerability-analysisexploitationweb-application-exploitation+2
8 days ago
ghostsplice preview

ghostsplice

GitHubasset-group/ghostsplice

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

data-exfiltrationsocial-engineeringred-teaming+3
69 days ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951
vulnerability-scannersvulnerability-analysisexploitation+3
8 days ago
HiTMS_steganography preview

HiTMS_steganography

GitHubryehr/hitms_steganography

Embed multiple secret messages in LLM chat token choices using arithmetic/Discop steganographic coders, with bit-exact decoding and steganalysis…

defensive-toolsdata-exfiltrationsteganography+4
322 days ago
Previous12…37Next