Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
OSCP Notes and Custom Dashboard preview

OSCP Notes and Custom Dashboard

GitLabwattocyber/oscp-notes-2026

OSCP notes vault + exam cockpit dashboard: merged technique notes, variable-filled command decks, machines, creds, and runbook for exam day. MIT.

curated-resourceseducationinformation-gathering+7
16 days ago
CVE-2025-50505 preview

CVE-2025-50505

GitHuba0yami/cve-2025-50505

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

command-and-controldns-analysisexploitation+8
201 year ago
wasmforge preview

wasmforge

GitHubpraetorian-inc/wasmforge

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

binary-analysiscommand-and-controlexploit-frameworks+9
1333 months ago
veneficus preview

veneficus

GitHubabraxas/veneficus

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

command-and-controldata-exfiltrationids-ips-evasion+8
21 month ago
CVE-2023-34051 preview

CVE-2023-34051

GitHubhorizon3ai/cve-2023-34051

VMware Aria Operations for Logs CVE-2023-34051

authenticationcommand-and-controlexploitation+7
602 years ago
Elite preview

Elite

GitHubcobbr/elite

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

command-and-controldynamic-code-analysisencryption-decryption-tools+6
1217 years ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
10 months ago
K8tools preview

K8tools

GitHubk8gege/k8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

command-and-controlexploit-frameworkslateral-movement+9
6.2k1 year ago
DLLHijackHunter preview

DLLHijackHunter

GitHubghostvectoracademy/dllhijackhunter

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

binary-analysisdynamic-code-analysiseducation+8
40722 days ago
Ivanti-EPM-Coercion-Vulnerabilities preview

Ivanti-EPM-Coercion-Vulnerabilities

GitHubhorizon3ai/ivanti-epm-coercion-vulnerabilities

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

exploitationlateral-movementpenetration-testing+2
131 year ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

container-escapectfcurated-resources+9
1 month ago
CVE-2026-6875-PoC-Exploit preview

CVE-2026-6875-PoC-Exploit

GitHubtc4dy/cve-2026-6875-poc-exploit

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

exploitationlateral-movementpenetration-testing+7
32 months ago
SharpShooter preview

SharpShooter

GitHubmdsecactivebreach/sharpshooter

Payload Generation Framework

command-and-controldns-analysisexploitation+9
2.0k2 years ago
Http-Asynchronous-Reverse-Shell preview
Archived

Http-Asynchronous-Reverse-Shell

GitHubonsec-fr/http-asynchronous-reverse-shell

[POC] Asynchronous reverse shell using the HTTP protocol.

command-and-controldata-exfiltrationids-ips-evasion+7
2721 year ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubanach-ai/cve-2026-41940

CVE-2026-41940 — cPanel/WHM Auth Bypass By Dr.Anach, CRLF injection in `cpsrvd` Basic auth handler → unauthenticated WHM API access → RCE as root.…

authentication-authorizationcommand-and-controlexploitation+7
4 months ago
PyLadon preview

PyLadon

GitHubk8gege/pyladon

Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection /…

command-and-controlexploitationlateral-movement+6
535 years ago
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
2 months ago
taowu-cobalt_strike preview

taowu-cobalt_strike

GitHubpandasec888/taowu-cobalt_strike

Red team automation framework built on Cobalt Strike, integrating exploit modules, post-exploitation tools, and lateral movement capabilities for…

command-and-controlexploit-frameworkslateral-movement+7
1.8k10 months ago
Previous1234Next