Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
19 results
BrokenFlow preview

BrokenFlow

GitHubenkomio/brokenflow

A simple PoC to invoke an encrypted shellcode by using an hidden call

binary-exploitationencryption-decryption-toolsexploitation+4
1153 years ago
tomcatWarDeployer preview

tomcatWarDeployer

GitHubmgeeky/tomcatwardeployer

Apache Tomcat auto WAR deployment & pwning penetration testing tool.

exploitationpayload-generationpenetration-testing+1
4473 years ago
Empire preview
Archived

Empire

GitHubempireproject/empire

Empire is a PowerShell and Python post-exploitation agent.

command-and-controlexploitationlateral-movement+6
7.9k6 years ago
invoker preview
Archived

invoker

GitHubivan-sincek/invoker

Penetration testing utility and antivirus assessment tool.

binary-analysiseducationexploitation+6
3123 years ago
Sharp-SMBExec preview

Sharp-SMBExec

GitHubcheckymander/sharp-smbexec

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

authenticationexploitationlateral-movement+1
2176 years ago
CVE-2026-75898 preview

CVE-2026-75898

GitHubt3bik/cve-2026-75898

Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

educationexploitationpapers-research+2
10 days ago
printix-CVE-2022-29554 preview

printix-CVE-2022-29554

GitHubcomparedarray/printix-cve-2022-29554

A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…

api-securityexploitationmisconfiguration+3
34 years ago
CVE-2025-48827 preview

CVE-2025-48827

GitHubsh4den/cve-2025-48827

This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin…

authenticationeducationexploitation+3
12 months ago
cve-2021-1675 preview

cve-2021-1675

GitHub000tonio/cve-2021-1675

PowerShell exploit for CVE-2021-1675 PrintNightmare that disables AMSI and creates a local administrator account on vulnerable Windows systems.

exploitationpayload-generationpenetration-testing+2
3 years ago
Invoke-BadSuccessor.ps1 preview

Invoke-BadSuccessor.ps1

GitHubb5null/invoke-badsuccessor.ps1

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

authenticationexploitationpenetration-testing+4
472 months ago
stealth_call preview

stealth_call

GitHubkitsune-de/stealth_call

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

anti-botdefensive-toolsexploitation+3
74 months ago
CVE-2025-7771 preview

CVE-2025-7771

GitHubgabriel-lacorte/cve-2025-7771

Arbitrary Function Call Exploit using the ThrottleStop driver

binary-exploitationexploitationprivilege-escalation+2
126 months ago
CVE-2020-36708 preview

CVE-2020-36708

GitHubb1g-b33f/cve-2020-36708

Proof of concept for CVE-2020-36708

educationexploitationpenetration-testing+2
21 year ago
Invoke-DCSync preview

Invoke-DCSync

GitHubal1ex/invoke-dcsync

Invoke-DCSync

exploitationlateral-movementpassword-attacks+3
15 years ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubxiaolvchen/cve-2025-54100

CVE-2025-54100(PowerShell 远程代码执行漏洞)

educationexploitationpayload-development+3
18 months ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubianthinus/cve-2024-4577

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

code-analysisexploitationpayload-generation+3
1 year ago
ABC preview

ABC

GitHubhzachev/abc

CVE-2017-11882

command-and-controlexploitationpayload-generation+2
8 years ago
CVE-2025-53691 preview

CVE-2025-53691

GitHubblueisbeautiful/cve-2025-53691

Remote code execution (RCE) through insecure deserialization

exploitationpayload-developmentpenetration-testing+2
1 year ago
Previous12Next