Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
327 results
enseal preview

enseal

GitHubfleralex/enseal

Secure, ephemeral secret sharing for developers.

authenticationcloud-securityconfiguration-auditing+6
55 months ago
Xworm RAT preview

Xworm RAT

GitLabmanturever/xworm-rat

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

command-and-controlcryptographydata-exfiltration+8
33 months ago
C2-and-Post-Exploitation-Framework preview

C2-and-Post-Exploitation-Framework

GitHubjacobtaylor3/c2-and-post-exploitation-framework

CVE-2021-21220 Exploitation infrastructure

command-and-controldata-exfiltrationeducation+8
4 months ago
Kotaemon-CVE-2025-56526-56527-disclosure preview

Kotaemon-CVE-2025-56526-56527-disclosure

GitHubhantul/kotaemon-cve-2025-56526-56527-disclosure

Public disclosure for CVE-2025-56526 and CVE-2025-56527 — Stored XSS via unsanitized PDF content rendering and plaintext credential exposure in…

data-exfiltrationeducationexploitation+5
110 months ago
CVE-2025-53770-Exploit preview

CVE-2025-53770-Exploit

GitHubudyz/cve-2025-53770-exploit

Exploit for CVE-2025-53770, a SharePoint ViewState deserialization vulnerability, enabling remote code execution via crafted payloads.

command-and-controldata-exfiltrationexploitation+3
11 year ago
CVE-2024-37383-exploit preview

CVE-2024-37383-exploit

GitHubamirzargham/cve-2024-37383-exploit

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

data-exfiltrationemail-securityexploitation+3
1 year ago
CVE-2024-51747 preview

CVE-2024-51747

GitHubl20170217b/cve-2024-51747

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…

database-securitydata-exfiltrationexploitation+2
1 year ago
ST3GG preview

ST3GG

GitHubelder-plinius/st3gg

All-in-one steganography suite

ai-securityctfdata-exfiltration+8
1.8k3 months ago
ESFileExplorerOpenPortVuln preview

ESFileExplorerOpenPortVuln

GitHubfs0c131y/esfileexploreropenportvuln

ES File Explorer Open Port Vulnerability - CVE-2019-6447

android-securitydata-exfiltrationexploitation+5
6787 years ago
BetterAndroRAT preview

BetterAndroRAT

GitHubmwsrc/betterandrorat

Android Remote Access Trojan

android-securitycommand-and-controldata-exfiltration+8
5459 years ago
rdroid preview

rdroid

GitHubhuntoai/rdroid

[Android RAT] Remotely manage your android phone using PHP Interface

android-securitycommand-and-controldata-exfiltration+3
2478 years ago
AndroidRAT preview

AndroidRAT

GitHubibrahimbalic/androidrat

Android RAT

android-securitydata-exfiltrationinformation-gathering+3
16213 years ago
HTTPUploadExfil preview

HTTPUploadExfil

GitHubingokl/httpuploadexfil

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

ctfdata-exfiltrationpenetration-testing+1
821 year ago
CVE-2024-23700-C2-Server preview

CVE-2024-23700-C2-Server

GitHubkaitokidc500/cve-2024-23700-c2-server

Source code minh họa máy chủ c2 demo kịch bản thực thi của CVE-2024-23700

android-securitycommand-and-controldata-exfiltration+9
22 days ago
keepass-exfil-forensics preview

keepass-exfil-forensics

GitHubpugazhendii22/keepass-exfil-forensics

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

ctfdata-exfiltrationdigital-forensics+6
1 month ago
CVE-2024-42009-roundcube-xss preview

CVE-2024-42009-roundcube-xss

GitHubsegunakinsoyinu/cve-2024-42009-roundcube-xss

Stored XSS exploit for Roundcube Webmail ≤1.6.6 (CVE-2024-42009) with zero-click email exfiltration via CSS animation event handlers. Includes SMTP…

ctfdata-exfiltrationeducation+4
2 months ago
CVE-2026-56782-Gorse-Auth-Bypass preview

CVE-2026-56782-Gorse-Auth-Bypass

GitHubbiitts/cve-2026-56782-gorse-auth-bypass

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

authenticationctfdata-exfiltration+6
12 months ago
CVE-2024-0044-EXP preview

CVE-2024-0044-EXP

GitHubkai2er/cve-2024-0044-exp

利用CVE-2024-0044 在Android12、13 没有root'下进行数据备份 用法./CVE-2024-0044-EXP.sh <package_name>

android-securitydata-exfiltrationexploitation+3
2 years ago
Previous1…171819Next