Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
shadow preview

shadow

GitHubcensus/shadow

jemalloc heap exploitation framework

binary-exploitationdebuggersexploitation+2
4694 years ago
Januscape preview

Januscape

GitHubv4bel/januscape

KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

binary-exploitationcloud-securityexploitation+4
5721 month ago
Zapscape preview

Zapscape

GitHubv4bel/zapscape

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

binary-exploitationcloud-securityexploitation+3
1661 month ago
windows_kernel_shadow_stack preview

windows_kernel_shadow_stack

GitHubsynacktiv/windows_kernel_shadow_stack

Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.

binary-exploitationexploitationpapers-research+2
771 year ago
CVE-2026-64561 preview

CVE-2026-64561

GitHubhackspeak/cve-2026-64561

Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing

binary-exploitationexploitationred-teaming+2
21 month ago
CVE-2021-36934-HiveNightmare-Lab preview

CVE-2021-36934-HiveNightmare-Lab

GitHubd4yon/cve-2021-36934-hivenightmare-lab

Educational lab demonstrating CVE-2021-36934 (HiveNightmare) - Windows LPE via shadow copy ACL misconfiguration.

binary-exploitationeducationexploitation+4
17 months ago
CVE-2026-53359 preview

CVE-2026-53359

GitHub0xblackash/cve-2026-53359

CVE-2026-53359

binary-exploitationeducationexploitation+2
42 months ago
honda preview

honda

GitLabnu11secur1ty/0

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

binary-exploitationexploitationpayload-development+3
3 months ago
CVE-2020-17382 preview

CVE-2020-17382

GitHubtypeconfused/cve-2020-17382

CVE-2020-17382 Windows 10 x64 2004 Build 19041.264 Exploit

binary-exploitationexploitationprivilege-escalation+1
13 years ago
Whisker preview

Whisker

GitHubeladshamir/whisker

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

authenticationexploitationpenetration-testing+4
9551 year ago
pywhisker preview

pywhisker

GitHubshutdownrepo/pywhisker

Python version of the C# tool for "Shadow Credentials" attacks

authenticationexploitationpenetration-testing+1
9413 months ago
ShadowSpray preview

ShadowSpray

GitHubdec0ne/shadowspray

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the…

authenticationexploitationpenetration-testing+3
4973 years ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
2089 days ago
poc_CVE-2021-36934 preview

poc_CVE-2021-36934

GitHubgrishinpv/poc_cve-2021-36934

POC experiments with Volume Shadow copy Service (VSS)

data-recoveryexploitationforensics+2
25 years ago
CVE-2021-36934 preview

CVE-2021-36934

GitHubbytesizedalex/cve-2021-36934

PowerShell scripts to detect and remediate CVE-2021-36934 privilege escalation vulnerability via SAM permission validation and VSS shadow copy…

configuration-auditingexploitationincident-response+3
25 years ago
CVE-2021-36934-export-shadow-volume-POC preview

CVE-2021-36934-export-shadow-volume-POC

GitHubolivierlaflamme/cve-2021-36934-export-shadow-volume-poc

Proof-of-concept exploit for CVE-2021-36934, exporting Windows Volume Shadow Copy files to enable privilege escalation and hash-based credential…

exploitationpassword-attackspost-exploitation+2
15 years ago
Why-so-Serious-SAM preview

Why-so-Serious-SAM

GitHubp1rat3r00t/why-so-serious-sam

PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

ctfeducationexploitation+6
1 year ago
CVE-2021-3773 preview

CVE-2021-3773

GitHubd0rb/cve-2021-3773

Exploit script for CVE-2021-3773 (Port Shadow) targeting OpenVPN servers using Netfilter NAT. Performs deanonymization and man-in-the-middle attacks…

educationexploitationnetwork-security+2
2 years ago
Previous12Next