Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
evil-winrm preview

evil-winrm

GitHubhackplayers/evil-winrm

The ultimate WinRM shell for hacking/pentesting

authenticationexploitationpayload-generation+3
5.5k
4 days ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
4113 days ago
larac2shell preview

larac2shell

GitHubakefallonitis/larac2shell

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

authenticationcommand-and-controlincident-response+6
164 months ago
CVE-2026-31816-rshell preview

CVE-2026-31816-rshell

GitHubimjdl/cve-2026-31816-rshell

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

authenticationexploitationpayload-development+2
5 months ago
ipmitest preview

ipmitest

GitHubalexoslabs/ipmitest

Shell script for testing the IPMI cipher type zero authentication bypass vulnerability (CVE-2013-4784)

authenticationexploitationhardware-security+3
11 years ago
bepr preview

bepr

GitHubaperocky/bepr

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

authenticationcommand-and-controlpenetration-testing+3
2 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubobrunolima1910/cve-2026-24061

🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.

authenticationeducationexploitation+3
5 days ago
CVE-2021-3156-Mitigation-ShellScript-Build preview

CVE-2021-3156-Mitigation-ShellScript-Build

GitHubajtech-hue/cve-2021-3156-mitigation-shellscript-build

Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

authenticationdefensive-toolsincident-response+2
5 years ago
sharepoint-toolshell-cve-2025-53770 preview

sharepoint-toolshell-cve-2025-53770

GitHubbharath-cyber-root/sharepoint-toolshell-cve-2025-53770

Exploit for CVE-2025-53770, a critical SharePoint RCE via authentication bypass and unsafe deserialization, enabling web shell deployment and machine…

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2018-10933-libSSH-Authentication-Bypass preview

CVE-2018-10933-libSSH-Authentication-Bypass

GitHublikekabin/cve-2018-10933-libssh-authentication-bypass

Exploit tool for CVE-2018-10933 libSSH authentication bypass, enabling remote shell access without credentials using Python scripts and optional fake…

authenticationexploitationnetwork-security+3
17 years ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubparad0x7e/cve-2026-24061

Exploit and scanner for CVE-2026-24061, a telnetd authentication bypass that grants root shell via crafted USER environment variable. Includes Docker…

authenticationexploitationnetwork-security+3
7 months ago
CVE-2021-3560-Polkit-Privilege-Esclation preview

CVE-2021-3560-Polkit-Privilege-Esclation

GitHubsecnigma/cve-2021-3560-polkit-privilege-esclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

authenticationexploitationpenetration-testing+2
1263 years ago
CVE-2026-24061-POC preview

CVE-2026-24061-POC

GitHubjayglxr/cve-2026-24061-poc

Proof-of-concept exploit for CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd via crafted NEW_ENVIRON USER variable,…

authenticationexploitationnetwork-security+3
677 months ago
CVE-2019-12476 preview

CVE-2019-12476

GitHub0katz/cve-2019-12476

PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted…

authenticationexploitationpenetration-testing+2
436 years ago
0-click-RCE-Exploit-for-CVE-2024-10924 preview

0-click-RCE-Exploit-for-CVE-2024-10924

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-10924

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

authenticationexploitationpayload-development+4
147 months ago
cve-2024-56348 preview

cve-2024-56348

GitHubjoshuavanderpoll/cve-2024-56348

Go-based exploit for CVE-2024-56348 targeting JetBrains TeamCity authentication bypass and remote code execution. Provides interactive shell, reverse…

authenticationexploitationpenetration-testing+4
36 months ago
CVE-2024-55591-POC preview

CVE-2024-55591-POC

GitHubumchacker/cve-2024-55591-poc

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

authenticationexploitationpenetration-testing+3
21 year ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubprzemytn/cve-2026-24061

Proof-of-concept exploit for CVE-2026-24061, a telnetd authentication bypass via argument injection in the USER environment variable, allowing…

authenticationexploitationnetwork-security+3
5 months ago
Previous12Next