Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
163 results
GhostTunnel preview

GhostTunnel

GitHubpegasuslab/ghosttunnel

Covert backdoor transmission tool using 802.11 probe request and beacon frames for isolated network attacks. Delivers payloads via HID devices,…

command-and-controlpost-exploitationred-teaming+1
335
7 years ago
Elevate-System-Trusted-BOF preview

Elevate-System-Trusted-BOF

GitHubmr-un1k0d3r/elevate-system-trusted-bof

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

command-and-controlpayload-developmentpost-exploitation+2
1813 years ago
CVE-2025-33053_PoC preview

CVE-2025-33053_PoC

GitHub4n4s4zi/cve-2025-33053_poc

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

command-and-controlexploitationlateral-movement+3
11 year ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2986 months ago
CVE-2025-53547-POC preview

CVE-2025-53547-POC

GitHubdvkunion/cve-2025-53547-poc

CVE-2025-53547 one of poc code

command-and-controlexploitationpayload-development+2
91 year ago
ActiveReign preview

ActiveReign

GitHubm8sec/activereign

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

command-and-controlexploitationinformation-gathering+2
2462 years ago
-EXPLOIT-CVE-2023-36025 preview

-EXPLOIT-CVE-2023-36025

GitHubcoolman6942o/-exploit-cve-2023-36025

Windows SmartScreen Security Feature Bypass Vulnerability

command-and-controlexploitationexploit-frameworks+2
52 years ago
SpawnWith preview

SpawnWith

GitHubrasta-mouse/spawnwith

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

command-and-controlimpersonation-toolslateral-movement+2
1131 year ago
CVE-2024-7399-POC preview

CVE-2024-7399-POC

GitHubdavidxbors/cve-2024-7399-poc

Python-based proof-of-concept exploit for CVE-2024-7399 with check, command execution, and file upload capabilities against HTTPS endpoints.

command-and-controlexploitationpenetration-testing+2
1 year ago
CVE-2025-58180 preview

CVE-2025-58180

GitHubprabhatverma47/cve-2025-58180

In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses…

command-and-controlexploitationpayload-generation+3
11 months ago
doublepulsar-c2-traffic-decryptor preview

doublepulsar-c2-traffic-decryptor

GitHubwithsecurelabs/doublepulsar-c2-traffic-decryptor

A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant

command-and-controlencryption-decryption-toolsexploitation+3
2259 years ago
motioneye-authenticated-RCE preview

motioneye-authenticated-RCE

GitHubpizza-power/motioneye-authenticated-rce

A Python 3 script that uploads a tasks.pickle file that enables RCE in MotionEye. CVE-2021-44255

command-and-controlexploitationpenetration-testing+3
13 years ago
DLPwn preview

DLPwn

GitHubgryfman/dlpwn

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

bluetooth-securitycommand-and-controldata-exfiltration+5
245 months ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubozcanpng/cve-2024-9264

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

command-and-controleducationexploitation+3
1 month ago
BlueSAM preview

BlueSAM

GitHubincursi0n/bluesam

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

command-and-controlexploitationpayload-development+3
1674 months ago
novahot preview
Archived

novahot

GitHubchrisallenlane/novahot

A webshell framework for penetration testers.

command-and-controlexploit-frameworkspayload-generation+3
2991 year ago
Daily-dose-of-malware preview

Daily-dose-of-malware

GitHubwoj-ciech/daily-dose-of-malware

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

command-and-controlinformation-gatheringmalware-analysis+2
408 years ago
CVE-2022-44877 preview

CVE-2022-44877

GitHubdkstar11q/cve-2022-44877

Bash script to detect and exploit CVE-2022-44877 command injection vulnerability in CentOS Web Panel, supporting single URL scanning, exploitation,…

command-and-controleducationexploitation+3
3 years ago
Previous12…10Next