Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
324 results
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k
4 months ago
skills preview

skills

GitHubspecterops/skills

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

command-and-controleducationexploitation+9
69312 days ago
TripleCross preview

TripleCross

GitHubh3xduck/triplecross

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

command-and-controleducationpersistence-mechanisms+1
2.0k3 years ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9867 days ago
lutlol preview

lutlol

GitHubmagisterquis/lutlol

Living Under the Land on Linux ~ Bsides Belfast/Vienna 2025

command-and-controleducationids-ips-evasion+3
3810 months ago
rvbbit-arsenal preview

rvbbit-arsenal

GitHubbuter-chkalova/rvbbit-arsenal

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

command-and-controldefensive-toolseducation+5
1616 days ago
THM-MagnusBilling-CVE-2023-30258-Exploit preview

THM-MagnusBilling-CVE-2023-30258-Exploit

GitHubcyb3rk0ala/thm-magnusbilling-cve-2023-30258-exploit

Step-by-step walkthrough exploiting CVE-2023-30258 (MagnusBilling RCE) and escalating privileges via fail2ban misconfiguration on a TryHackMe lab.…

command-and-controlctfeducation+7
1 month ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubsyrins/cve-2025-55182-react2shell-rce

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

command-and-controleducationexploitation+4
310 months ago
Drupalgeddon2-CVE-2018-7600 preview

Drupalgeddon2-CVE-2018-7600

GitHubbixipro/drupalgeddon2-cve-2018-7600

Python exploit for CVE-2018-7600 (Drupalgeddon 2) enabling remote code execution on Drupal 7 with multiple injection methods and predefined commands…

command-and-controleducationexploitation+3
7 months ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

command-and-controleducationexploitation+7
10 months ago
ToRat preview
Archived

ToRat

GitHubluantak/torat

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

command-and-controleducationpayload-generation+6
1.0k3 years ago
CVE-2022-37706-LPE-exploit preview

CVE-2022-37706-LPE-exploit

GitHubmaherazzouzi/cve-2022-37706-lpe-exploit

A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)

binary-exploitationcommand-and-controleducation+5
3234 years ago
Phantom-Evasion-Loader preview

Phantom-Evasion-Loader

GitHubjm00nj/phantom-evasion-loader

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

binary-exploitationcommand-and-controleducation+6
1132 months ago
exploit-CVE-2022-25765 preview

exploit-CVE-2022-25765

GitHubunicordev/exploit-cve-2022-25765

Exploit for CVE-2022–25765 (pdfkit) - Command Injection

command-and-controleducationexploitation+4
311 year ago
Stealth-Kid-RAT preview

Stealth-Kid-RAT

GitHubartbitrage/stealth-kid-rat

Stealth Kid RAT (SKR) is an open-source multi-platform Remote Access Trojan (RAT) written in C#. Released under MIT license. The SKR project is fully…

command-and-controleducationpayload-development+3
245 years ago
R2C-CVE-2025-55182-66478 preview

R2C-CVE-2025-55182-66478

GitHubcybertechajju/r2c-cve-2025-55182-66478

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+8
2410 months ago
Follina preview

Follina

GitHubabdulrkb/follina

Demonstration of Windows MSDT Vulnerability (CVE-2022-30190)

command-and-controleducationexploitation+4
52 years ago
velociraptor_CVE-2025-6264_PoC preview

velociraptor_CVE-2025-6264_PoC

GitHubmauzy0x00/velociraptor_cve-2025-6264_poc

Proof-of-concept exploit for CVE-2025-6264 in Velociraptor, demonstrating privilege escalation via missing permission checks to redirect clients to a…

command-and-controleducationexploitation+3
5 months ago
Previous12…18Next