Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
magicNetdefs preview

magicNetdefs

GitHubcrisprss/magicnetdefs

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

adversarial-attackauthenticationexploitation+3
49
4 years ago
CVE-2026-2828-WebGPU-Cross-Origin-Pixel-Stealing-via-Timing preview

CVE-2026-2828-WebGPU-Cross-Origin-Pixel-Stealing-via-Timing

GitHubgeorge0papasotiriou/cve-2026-2828-webgpu-cross-origin-pixel-stealing-via-timing
adversarial-attackdata-exfiltrationexploitation+3
22 days ago
PoisonCraft preview

PoisonCraft

GitHubandyshaw01/poisoncraft

This repository provides the official implementation of POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models.

adversarial-attackai-securityexploitation+3
111 year ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubhackspeak/cve-2026-64638

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing

adversarial-attackexploitationpayload-generation+4
116 days ago
Mystikal preview

Mystikal

GitHubd00mfist/mystikal

macOS Initial Access Payload Generator

adversarial-attackcommand-and-controlpayload-development+4
3262 years ago
CVE-2025-32432-PoC preview

CVE-2025-32432-PoC

GitHubezramansor/cve-2025-32432-poc

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

adversarial-attackexploitationpayload-generation+3
17 days ago
ShellcodeFluctuation preview

ShellcodeFluctuation

GitHubmgeeky/shellcodefluctuation

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

adversarial-attackpayload-developmentpayload-generation+4
1.1k4 years ago
anamorpher preview

anamorpher

GitHubtrailofbits/anamorpher

image scaling attacks for multi-modal prompt injection

adversarial-attackai-securitymachine-learning+1
1.1k6 months ago
Pokemon-Shellcode-Loader preview

Pokemon-Shellcode-Loader

GitHubtechryptic/pokemon-shellcode-loader

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

adversarial-attackpayload-developmentpayload-generation+3
1284 years ago
DotNET_XorCryptor preview

DotNET_XorCryptor

GitHubdosx-dev/dotnet_xorcryptor

A new simple and powerfull packer for malware

adversarial-attackcryptographypayload-development+1
1072 years ago
blenny preview

blenny

GitHubfrank2/blenny

A payload delivery system which embeds payloads in an executable's icon file!

adversarial-attackpayload-developmentpayload-generation+2
742 years ago
the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex preview

the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex

GitHubhunt-benito/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex
adversarial-attackexploitationpayload-generation+3
11 days ago
ThreadlessInject preview

ThreadlessInject

GitHubccob/threadlessinject

Threadless Process Injection using remote function hooking.

adversarial-attackpayload-developmentpayload-generation+4
8251 year ago
detection-validation preview

detection-validation

GitHubalwashali/detection-validation

Detection rule validation

adversarial-attackdefensive-toolsintrusion-detection+1
422 years ago
RTA preview

RTA

GitHubendgameinc/rta
adversarial-attackeducationlabs-practice+2
1.1k8 years ago
Windows-SignedBinary preview

Windows-SignedBinary

GitHubmr-un1k0d3r/windows-signedbinary
adversarial-attackbinary-analysishash-analysis+4
2607 years ago
NachoVPN preview

NachoVPN

GitHubamberwolfcyber/nachovpn

A delicious, but malicious SSL-VPN server 🌮

adversarial-attackexploitationnetwork-security+5
2685 months ago
Lockbit3.0-MpClient-Defender-PoC preview

Lockbit3.0-MpClient-Defender-PoC

GitHubsh0ckfr/lockbit3.0-mpclient-defender-poc

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

adversarial-attackexploitationmalware-analysis+2
1754 years ago
Previous12Next