Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
134 results
chainoffools preview

chainoffools

GitHubkudelskisecurity/chainoffools

Proof-of-concept exploit for CVE-2020-0601 Windows CryptoAPI spoofing vulnerability, demonstrating rogue CA certificate generation using elliptic…

code-analysiscryptographyexploitation+2
335
3 years ago
log4j_checker_beta preview

log4j_checker_beta

GitHubrubo77/log4j_checker_beta

a fast check, if your server could be vulnerable to CVE-2021-44228

code-analysisdynamic-analysis-sandboxingincident-response+3
2464 years ago
opentaint preview

opentaint

GitHubseqra/opentaint

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

ai-securityapi-securitycode-analysis+7
1605 days ago
windbg-decompile-ext preview

windbg-decompile-ext

GitHubkernullist/windbg-decompile-ext

WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.

ai-assisted-reversingbinary-analysisbinary-exploitation+8
1113 months ago
JObfuscator preview

JObfuscator

GitHubpelock/jobfuscator

Obfuscates Java source code to protect against reverse engineering, decompilation, and IP theft. Renames variables/methods, encrypts strings, and…

code-analysiscryptographyreverse-engineering+1
682 months ago
CVE-2025-27237 preview

CVE-2025-27237

GitHubhackinglz/cve-2025-27237

CVE 2025 27237 Zabbix LPE proof of concept.

binary-analysiscode-analysisexploitation+3
198 months ago
kyubisweep preview

kyubisweep

GitHubtanmayshahane/kyubisweep

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

code-analysisconfiguration-auditingdevsecops+3
49 months ago
CVE-2021-26871_POC preview

CVE-2021-26871_POC

GitHubfr4nkxixi/cve-2021-26871_poc

Proof-of-concept exploit for CVE-2021-26871, a type confusion vulnerability in Windows WalletService's PROPVARIANT handling, enabling local privilege…

binary-exploitationcode-analysisexploitation+2
35 years ago
TriBell_Edge_SandBox_Escape preview

TriBell_Edge_SandBox_Escape

GitHubkai6u/tribell_edge_sandbox_escape

Tribell Edge Sandbox Escape - PoCs of Edge's legacy vulnerabilities BadgeUpdateManager / TileFlyoutUpdateManager / ToastNotificationManager to…

binary-exploitationcode-analysisexploitation+3
51 year ago
-CVE-2020-0601-ECC---EXPLOIT preview

-CVE-2020-0601-ECC---EXPLOIT

GitHubiiictech/-cve-2020-0601-ecc---exploit

CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using…

binary-exploitationcode-analysiscryptography+3
36 years ago
opencode-secure preview

opencode-secure

GitHubbarrersoftware/opencode-secure

Security-hardened fork of OpenCode - Fixes CVE-2026-22812 (CVSS 8.8 RCE) that upstream refuses to patch

code-analysisdevsecopssupply-chain-security+1
68 months ago
poc-cve-2018-1273 preview

poc-cve-2018-1273

GitHubwebr0ck/poc-cve-2018-1273

Proof-of-concept exploit for CVE-2018-1273, a Spring Data Commons property binder vulnerability leading to remote code execution via crafted HTTP…

code-analysisexploitationpenetration-testing+2
28 years ago
CVE-2026-12277 preview

CVE-2026-12277

GitHubmoritakaaz/cve-2026-12277

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE

code-analysisexploitationpayload-development+4
3 months ago
CVE-2023-50071 preview

CVE-2023-50071

GitHubgeraldoalcantara/cve-2023-50071

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department in Customer Support System 1.0 allow authenticated…

code-analysisdatabase-securityexploitation+3
32 years ago
gmh5225 preview

gmh5225

GitHubgmh5225/gmh5225

LLVM-based security research toolchain: NeverC, a C23 cross-compiler, and NeverD, a binary analysis and decompilation engine that lifts PE, ELF,…

ai-assisted-reversingbinary-analysisbinary-exploitation+4
1 month ago
CVE-2026-14361 preview

CVE-2026-14361

GitHub0xmrma/cve-2026-14361

Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output…

code-analysiseducationexploitation+1
2 months ago
CVE-2023-29007_win-version preview

CVE-2023-29007_win-version

GitHubx-defender/cve-2023-29007_win-version

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation on Windows systems for…

code-analysisexploitationpenetration-testing+2
23 years ago
CVE-2020-0601 preview

CVE-2020-0601

GitHubyanghaoi/cve-2020-0601

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

binary-exploitationcode-analysiscryptography+3
15 years ago
Previous123…8Next