Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Data Exfiltration

Tools for extracting sensitive data from compromised systems without detection.

NewestRelevanceMost popularRecently updated
649 results
Apache-Solr-Arbitrary-File-Read preview

Apache-Solr-Arbitrary-File-Read

GitHubmurataydemir/apache-solr-arbitrary-file-read

[No CVE] Apache Solr Arbitrary File Read

vulnerability-analysisexploitationweb-application-exploitation+4
1
5 years ago
gh-hijack-runner preview

gh-hijack-runner

GitHubsynacktiv/gh-hijack-runner

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

exploitationdata-exfiltrationpenetration-testing+3
331 year ago
Collabfiltrator preview

Collabfiltrator

GitHub0xc01df00d/collabfiltrator

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

payload-generationexploitationweb-application-exploitation+3
2801 year ago
Active-Directory-Exploitation-Cheat-Sheet preview

Active-Directory-Exploitation-Cheat-Sheet

GitHubintegration-it/active-directory-exploitation-cheat-sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

privilege-escalationreconnaissancepersistence-mechanisms+6
2.8k1 year ago
miniupnpd_poc preview

miniupnpd_poc

GitHubb1ack0wl/miniupnpd_poc

Read out-of-bounds PoC for miniupnpd <= v2.1

embedded-systems-securityiot-securityvulnerability-analysis+3
217 years ago
keebcap preview

keebcap

GitHubsynacktiv/keebcap

Win32 keylogger that supports all (non-ime using) languages correctly

password-attacksdata-exfiltrationinformation-gathering+2
552 years ago
CVE-2025-9223 preview

CVE-2025-9223

GitHubnetworkkiller/cve-2025-9223

POC CVE-2025-9223

vulnerability-analysisexploitationweb-application-exploitation+4
29 months ago
ecologyExp.jar preview

ecologyExp.jar

GitHubianxtianxt/ecologyexp.jar

泛微oa数据库配置文件读取

encryption-decryption-toolsvulnerability-analysisweb-application-exploitation+3
176 years ago
glpi-logbleed preview

glpi-logbleed

GitHub5kr1pt/glpi-logbleed

PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter

vulnerability-analysisexploitationweb-application-exploitation+2
125 days ago
rails-forensics-CVE-2026-66066 preview

rails-forensics-CVE-2026-66066

GitHubrails/rails-forensics-cve-2026-66066

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

vulnerability-analysisdata-exfiltrationweb-security+3
2320 days ago
nord-stream preview

nord-stream

GitHubsynacktiv/nord-stream

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

exploitationimpersonation-toolsdata-exfiltration+5
3701 month ago
CVE-2024-28987 preview

CVE-2024-28987

GitHubdarabium/cve-2024-28987

**CVE-2024-28987** is a critical vulnerability in SolarWinds Web Help Desk (WHD) that allows remote attackers to access sensitive ticket information…

vulnerability-analysisexploitationweb-application-exploitation+2
123 days ago
lame_old_keylogger preview

lame_old_keylogger

GitHubspiralbl0ck/lame_old_keylogger

lame old keylogger

password-attacksdata-exfiltrationpost-exploitation
4 years ago
exfil-scan preview

exfil-scan

GitHubvikasudasi/exfil-scan

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

data-exfiltrationdevsecopssecret-detection+2
626 days ago
CVE-2026-22804 preview

CVE-2026-22804

GitHubthemehackers/cve-2026-22804

This repository contains a Proof of Concept (PoC) exploit for the Stored Cross-Site Scripting (XSS) vulnerability in Termix, which can lead to Local…

vulnerability-analysisexploitationweb-application-exploitation+2
27 months ago
sqlwinds preview

sqlwinds

GitHubblue0x1/sqlwinds

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

privilege-escalationpersistence-mechanismsexploitation+7
11 months ago
gimmepatz preview

gimmepatz

GitHub6mile/gimmepatz

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

authentication-authorizationreconnaissancedata-exfiltration+7
431 year ago
CVE-2026-Discord preview

CVE-2026-Discord

GitHubnicetop1027/cve-2026-discord
persistence-mechanismsvulnerability-analysisexploitation+3
6 months ago
Previous1…789…37Next