Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
nightcrawler preview

nightcrawler

GitHubgaragehq/nightcrawler

Local AI powered red teamer on a phone

ai-securitycommand-and-controlexploitation+7
8232 months ago
pentest-harness preview

pentest-harness

GitHubs1n6h/pentest-harness

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

ai-securitycommand-and-controlctf+7
40726 days ago
SockTail preview

SockTail

GitHubyeeb1/socktail

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

command-and-controllateral-movementnetwork-security+4
5711 year ago
redshell preview

redshell

GitHubverizon/redshell

An interactive command prompt for red teaming and pentesting. Automatically pushes commands through SOCKS4/5 proxies via proxychains. Optional Cobalt…

command-and-controlpenetration-testingred-teaming
2274 years ago
dig preview

dig

GitHubxsser/dig

macOS dig wrapper that appends spoofed local TXT records to DNS query output, designed to deceive LLM agents into performing automated penetration…

command-and-controldns-analysisinformation-gathering+3
10625 days ago
react2shell-ultimate preview

react2shell-ultimate

GitHubhackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

command-and-controlexploitationpayload-generation+4
15610 months ago
CVE-2026-58635-PoC preview

CVE-2026-58635-PoC

GitHubdavidcarliez/cve-2026-58635-poc

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

binary-exploitationcommand-and-controlexploitation+5
302 months ago
CVE-2025-50505 preview

CVE-2025-50505

GitHuba0yami/cve-2025-50505

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

command-and-controldns-analysisexploitation+8
200 years ago
CVE-2020-28243 preview

CVE-2020-28243

GitHubstealthcopter/cve-2020-28243

CVE-2020-28243 Local Privledge Escalation Exploit in SaltStack Minion

command-and-controlexploitationpenetration-testing+3
205 years ago
CVE-2026-48732-poc preview

CVE-2026-48732-poc

GitHubsaku0512/cve-2026-48732-poc

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

command-and-controleducationexploitation+3
3 months ago
CVE-2025-65964 preview

CVE-2025-65964

GitHubsaboor-hakimi-23/cve-2025-65964

Educational CTF demo demonstrating command execution via Git hooks by abusing core.hooksPath in automation workflows. Highlights local hook execution…

command-and-controlctfeducation+3
9 months ago
CVE-2025-1910-WatchGuard-Privilege-Escalation preview

CVE-2025-1910-WatchGuard-Privilege-Escalation

GitHublutrasecurity/cve-2025-1910-watchguard-privilege-escalation

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

command-and-controlexploitationlateral-movement+6
8 months ago
CVE-2024-55503 preview

CVE-2024-55503

GitHubsyfi/cve-2024-55503

Proof-of-concept exploit for CVE-2024-55503, a local command injection in Termius for macOS via DYLD_INSERT_LIBRARIES, demonstrating arbitrary code…

binary-exploitationcommand-and-controlexploitation+3
1 year ago
CVE-2023-27532-RCE-Only preview

CVE-2023-27532-RCE-Only

GitHubpuckiestyle/cve-2023-27532-rce-only

Proof-of-concept exploit for CVE-2023-27532 enabling remote command execution with local system privileges on Veeam Backup & Replication servers.

command-and-controlexploitationpenetration-testing+3
2 years ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
Invoke-SocksProxy preview

Invoke-SocksProxy

GitHubp3nt4/invoke-socksproxy

Socks proxy, and reverse socks server using powershell.

command-and-controllateral-movementnetwork-security+2
80910 months ago
Maestro preview

Maestro

GitHubmayyhem/maestro

Abusing Azure services over C2

authenticationcloud-securitycommand-and-control+4
3828 months ago
RpcProxyInvoke preview

RpcProxyInvoke

GitHubklezvirus/rpcproxyinvoke

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

binary-exploitationcommand-and-controlexploitation+8
1392 years ago
Previous12Next