Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
128 results
CPLDCOMTrigger preview

CPLDCOMTrigger

GitHubklsecservices/cpldcomtrigger

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

exploitationlateral-movementpenetration-testing+2
48
9 months ago
CVE-2024-38472 preview

CVE-2024-38472

GitHubabdurahmon3236/cve-2024-38472

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

command-and-controlexploit-frameworkslateral-movement+6
42 years ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubuziii2208/cve-2025-33073

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.

ctfexploitationexploit-frameworks+4
6710 months ago
CVE-2021-21300 preview

CVE-2021-21300

GitHubfengzhouc/cve-2021-21300

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

command-and-controlexploitationlateral-movement+6
5 years ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubkagancapar/cve-2022-29072

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

binary-exploitationcommand-and-controlexploitation+5
6724 years ago
nosferatu preview

nosferatu

GitHubkindtime/nosferatu

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

authenticationlateral-movementpenetration-testing+2
2411 year ago
RedTeaming-Tactics-and-Techniques preview

RedTeaming-Tactics-and-Techniques

GitHubmantvydasb/redteaming-tactics-and-techniques

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

educationexploitationlabs-practice+8
4.7k3 months ago
Check-LocalAdminHash preview

Check-LocalAdminHash

GitHubdafthack/check-localadminhash

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

information-gatheringlateral-movementpassword-attacks+2
1797 years ago
caldera-agent preview
Archived

caldera-agent

GitHubmitre/caldera-agent

Windows service agent for CALDERA adversary emulation platform. Installed on target computers to communicate with the CALDERA server, enabling…

command-and-controllateral-movementpayload-generation+3
208 years ago
IHxExec preview

IHxExec

GitHubcicada8-research/ihxexec

Process injection alternative

exploitationlateral-movementpenetration-testing+3
4042 years ago
CVE-2021-34527 preview

CVE-2021-34527

GitHubm8sec/cve-2021-34527

PrintNightmare (CVE-2021-34527) PoC Exploit

exploitationlateral-movementpayload-generation+3
1183 years ago
PowerPriv preview

PowerPriv

GitHubg0ldengunsec/powerpriv

A Powershell implementation of PrivExchange designed to run under the current user's context

authenticationexploitationlateral-movement+2
1257 years ago
NamedPipePTH preview

NamedPipePTH

GitHubs3cur3th1ssh1t/namedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+4
1465 years ago
CVE-2025-26264 preview

CVE-2025-26264

GitHubhxlxmj/cve-2025-26264

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…

exploitationlateral-movementpenetration-testing+3
1 year ago
CVE-2020-8559 preview

CVE-2020-8559

GitHubtdwyer/cve-2020-8559

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

cloud-securitycontainer-securityexploitation+5
536 years ago
CobaltStrike-Toolset preview

CobaltStrike-Toolset

GitHubqax-a-team/cobaltstrike-toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

command-and-controlexploit-frameworkslateral-movement+8
5957 years ago
HTB-Mailing-A-Complete-Walkthrough preview

HTB-Mailing-A-Complete-Walkthrough

GitHubthemursalin/htb-mailing-a-complete-walkthrough

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…

ctfeducationexploitation+8
6 months ago
CVE-2024-32002 preview

CVE-2024-32002

GitHubcharlesgargasson/cve-2024-32002

Exploit for CVE-2024-32002, a Git RCE vulnerability that uses recursive submodule cloning and symlinks to execute arbitrary commands on Windows and…

command-and-controlexploitationlateral-movement+6
2 years ago
Previous12…8Next