Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5736 results
GoPurple preview

GoPurple

GitHubsh4hin/gopurple

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

defensive-toolseducationexploitation+6
497
5 years ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubmelonlonmeo/cve-2025-49132

Poc - CVE-2025-49132

configuration-auditingexploitationinformation-gathering+3
1 year ago
UACME preview

UACME

GitHubhfiref0x/uacme

Defeating Windows User Account Control

educationexploitationprivilege-escalation+1
7.8k1 month ago
widevine-l3-decryptor preview
Archived

widevine-l3-decryptor

GitHubtomer8007/widevine-l3-decryptor

A Chrome extension that demonstrates bypassing Widevine L3 DRM

binary-analysiseducationencryption-decryption-tools+3
1.2k3 years ago
MongoBleed-exploit preview

MongoBleed-exploit

GitHubeljoamy/mongobleed-exploit

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

ctfdatabase-securityeducation+5
7 months ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.4k17 days ago
device-activity-tracker preview

device-activity-tracker

GitHubgommzystudio/device-activity-tracker

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

educationexploitationinformation-gathering+7
5.1k7 months ago
METATRON preview

METATRON

GitHubsooryathejas/metatron

AI-powered penetration testing assistant using local LLM on linux (Parrot OS)

ai-securityeducationexploitation+5
3.6k4 months ago
Kali-Linux preview

Kali-Linux

GitHubnu11secur1ty/kali-linux

Kali Linux advanced setup

educationexploitationinformation-gathering+5
15817 days ago
CookieCatcher preview

CookieCatcher

GitHubdisk0nn3ct/cookiecatcher

CookieCatcher

educationexploitationphishing-tools+1
14612 years ago
TimeAfterFree preview

TimeAfterFree

GitHubm0x41nos/timeafterfree

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

binary-exploitationeducationexploitation+3
965 months ago
CVE-2026-50343-InstallService-EoP preview

CVE-2026-50343-InstallService-EoP

GitHubrat5ak/cve-2026-50343-installservice-eop

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

binary-exploitationeducationexploitation+3
481 month ago
CVE-2026-41089-Netlogon-RCE preview

CVE-2026-41089-Netlogon-RCE

GitHubhydrasoft/cve-2026-41089-netlogon-rce

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows…

educationexploitationincident-response+4
163 days ago
CVE-2026-31431-Metasploit-exploit preview

CVE-2026-31431-Metasploit-exploit

GitHubadityasingh108/cve-2026-31431-metasploit-exploit

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…

binary-exploitationeducationexploitation+7
23 months ago
CVE-2026-44401 preview

CVE-2026-44401

GitHubsn0x-sharma/cve-2026-44401

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

educationexploitationpenetration-testing+3
215 days ago
CVE-PoC-Hub preview

CVE-PoC-Hub

GitHubjavokhir-sec/cve-poc-hub

🛡️ CVE Proof-of-Concept Hub — 4 PUBLISHED CVEs · 5 under review (VulnCheck) · SuiteCRM batch withdrawn

ctfeducationexploitation+4
213 days ago
CVE-2021-4034 preview

CVE-2021-4034

GitHubdevianntsec/cve-2021-4034

Master's thesis research on CVE-2021-4034 (PwnKit) local privilege escalation. Multi-payload Python exploit with 7 modes including interactive shell,…

binary-exploitationeducationexploitation+7
14 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
Previous12…100Next