Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
300 results
exploit_cve-2021-29447 preview

exploit_cve-2021-29447

GitHubmega8bit/exploit_cve-2021-29447

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…

educationexploitationpenetration-testing+2
7
3 years ago
PPLcontrol preview

PPLcontrol

GitHubitm4n/pplcontrol

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

defensive-toolsexploitationprivilege-escalation+1
4073 years ago
ZeroLogon-to-Shell preview

ZeroLogon-to-Shell

GitHubc3rrberu5/zerologon-to-shell

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

exploitationpassword-crackingpenetration-testing+3
3 years ago
ccat preview

ccat

GitHubrhinosecuritylabs/ccat

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

cloud-securitycontainer-securityexploitation+1
6536 years ago
poc-cve-2026-32255 preview

poc-cve-2026-32255

GitHubkoadt/poc-cve-2026-32255

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

educationexploitationpenetration-testing+3
26 months ago
CVE-2020-17144 preview

CVE-2020-17144

GitHubzcgonvh/cve-2020-17144

weaponized tool for CVE-2020-17144

command-and-controlexploitationpayload-generation+2
1585 years ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
13 days ago
CVE-2017-8225 preview

CVE-2017-8225

GitHubkienquoc102/cve-2017-8225

Exploit tool for CVE-2017-8225 targeting IP cameras. Scans for vulnerable devices and performs credential brute-forcing to gain unauthorized access.

exploitationinformation-gatheringiot-security+2
24 years ago
CVE-2021-31761 preview

CVE-2021-31761

GitHubmesh3l911/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

exploitationpenetration-testingremote-access-tool+2
55 years ago
CVE-2024-12856 preview

CVE-2024-12856

GitHubnu113d/cve-2024-12856

An exploit for Four-Faith routers to get a reverse shell

exploitationpenetration-testingremote-access-tool+2
31 year ago
Salsa-tools preview

Salsa-tools

GitHubhackplayers/salsa-tools

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

command-and-controlencryption-decryption-toolsexploitation+7
5906 years ago
EvilWinRM-NG preview

EvilWinRM-NG

GitLabceald1/evilwinrm-ng

Go-based WinRM client for remote command execution and lateral movement on Windows systems during penetration tests.

exploitationpenetration-testingremote-access-tool
22 years ago
CVE-2022-46169 preview

CVE-2022-46169

GitHub0xn7y/cve-2022-46169

Exploit for CVE-2022-46169

authentication-authorizationcommand-and-controlexploitation+3
12 years ago
CVE-2019-0708-Tool preview

CVE-2019-0708-Tool

GitHubsqldebugger/cve-2019-0708-tool

50 first stargazers will get get the tool via email

exploitationpenetration-testingred-teaming+2
7 years ago
udp-hunter preview

udp-hunter

GitHubnotsosecure/udp-hunter

Network assessment tool for various UDP Services covering both IPv4 and IPv6 protocols

exploitationinformation-gatheringnetwork-security+3
1176 years ago
CVE-2026-18953 preview

CVE-2026-18953

GitHubronamosa/cve-2026-18953

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

api-securityexploitationpenetration-testing+1
2 months ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubsoledad208/cve-2018-10933

CVE-2018-10933 very simple POC

authentication-authorizationexploitationpayload-generation+3
1267 years ago
CVE-2018-10933_ssh preview

CVE-2018-10933_ssh

GitHublikekabin/cve-2018-10933_ssh

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

authentication-authorizationexploitationpenetration-testing+3
7 years ago
Previous12…17Next