Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
327 results
SAMDump preview

SAMDump

GitHubricardojoserf/samdump

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Crystal, Python,…

data-exfiltrationencryption-decryption-toolspost-exploitation+3
386
15 days ago
KeeFarceReborn preview

KeeFarceReborn

GitHubd3lb3/keefarcereborn

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

data-exfiltrationpassword-attackspayload-generation+3
2993 years ago
MoreImpacketExamples preview

MoreImpacketExamples

GitHubicyguider/moreimpacketexamples

More examples using the Impacket library designed for learning purposes.

data-exfiltrationeducationlateral-movement+3
2653 years ago
PixelCode-Attack preview

PixelCode-Attack

GitHubs3n4t0r-0x0/pixelcode-attack

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

command-and-controldata-exfiltrationeducation+8
1757 months ago
Boucle-framework preview

Boucle-framework

GitHubbande-a-bonnot/boucle-framework

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

ai-securityconfiguration-auditingdata-exfiltration+3
1242 days ago
css-the-bomb-inside-your-inbox preview

css-the-bomb-inside-your-inbox

GitHubportswigger/css-the-bomb-inside-your-inbox

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

ai-securitycurated-resourcesdata-exfiltration+7
391 month ago
CVE-2020-11579 preview

CVE-2020-11579

GitHubshieldersec/cve-2020-11579

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

database-securitydata-exfiltrationexploitation+3
252 years ago
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

cloud-securitycommand-and-controldata-exfiltration+5
26 days ago
multicat preview

multicat

GitHubdakotanelson/multicat

PoC RAT using the sneaky-creeper data exfiltration library

command-and-controldata-exfiltrationpayload-development+3
310 years ago
CVE-2024-42009 preview

CVE-2024-42009

GitHub0xbassiouny1337/cve-2024-42009

This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail…

data-exfiltrationeducationexploitation+3
41 year ago
POC-CVE-2025-24104-Py preview

POC-CVE-2025-24104-Py

GitHubmissaels235/poc-cve-2025-24104-py

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

data-exfiltrationeducationexploitation+4
31 year ago
AdTran-Personal-Phone-Manager-Vulns preview

AdTran-Personal-Phone-Manager-Vulns

GitHub3ndg4me/adtran-personal-phone-manager-vulns

A repository hosting write ups for the 0 days CVE-2021-25679, CVE-2021-25680, and CVE-2021-25681

data-exfiltrationeducationexploitation+3
35 years ago
CVE-2026-5061 preview

CVE-2026-5061

GitHub0xmrma/cve-2026-5061

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

code-analysisdata-exfiltrationeducation+2
11 month ago
CVE-2024-33901-ProofOfConcept preview

CVE-2024-33901-ProofOfConcept

GitHubgmikisilva/cve-2024-33901-proofofconcept

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

data-exfiltrationdigital-forensicsexploitation+3
21 year ago
CVE-2026-35029-PoC preview

CVE-2026-35029-PoC

GitHublearner202649/cve-2026-35029-poc

The code for personally reproducing the corresponding vulnerability

data-exfiltrationeducationexploitation+4
3 months ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
9 months ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
5835 days ago
Http-Asynchronous-Reverse-Shell preview
Archived

Http-Asynchronous-Reverse-Shell

GitHubonsec-fr/http-asynchronous-reverse-shell

[POC] Asynchronous reverse shell using the HTTP protocol.

command-and-controldata-exfiltrationids-ips-evasion+7
2721 year ago
Previous1…151617…19Next