Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
34 results
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

cloud-securitycontainer-securityeducation+7
14 days ago
Red-Team-Infrastructure-Wiki preview

Red-Team-Infrastructure-Wiki

GitHubbluscreenofjeff/red-team-infrastructure-wiki

Wiki to collect Red Team infrastructure hardening resources

cloud-infrastructure-securitycommand-and-controlcurated-resources+5
4.5k11 months ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

cloud-securitycommand-and-controlencryption-decryption-tools+6
398 days ago
log4shell preview

log4shell

GitHubjxerome/log4shell

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

educationexploitationlabs-practice+3
4 years ago
copy-fail-CVE-2026-31431 preview

copy-fail-CVE-2026-31431

GitHubmorton-li/copy-fail-cve-2026-31431

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel privilege escalation, with x86_64, AArch64, and C payloads to obtain root on affected…

binary-exploitationexploitationpayload-development+2
3 months ago
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

cloud-securitycommand-and-controldata-exfiltration+5
15 days ago
Azure-App-Tools preview

Azure-App-Tools

GitHubrvrsh3ll/azure-app-tools

Collection of tools to use with Azure Applications

authenticationcloud-securitycommand-and-control+4
1132 years ago
CVE-2026-22008-AWS-Lambda-Layer-Injection-via-Shared-Layer-ARN preview

CVE-2026-22008-AWS-Lambda-Layer-Injection-via-Shared-Layer-ARN

GitHubgeorge0papasotiriou/cve-2026-22008-aws-lambda-layer-injection-via-shared-layer-arn

Proof-of-concept for CVE-2026-22008 demonstrating AWS Lambda layer injection via untrusted ARNs, enabling arbitrary code execution and credential…

cloud-infrastructure-securitycloud-securityexploitation+3
1 month ago
aad-bofs preview

aad-bofs

GitHubkozmer/aad-bofs

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

adversarial-attackcloud-infrastructure-securitycloud-security+5
1429 months ago
Ubuntu-0day preview

Ubuntu-0day

GitHubjas502n/ubuntu-0day

all 4.4 ubuntu aws instances are vulnerable

binary-exploitationexploitationpayload-development+2
658 years ago
ChromeAlone preview

ChromeAlone

GitHubpraetorian-inc/chromealone

A tool to transform Chromium browsers into a C2 Implant

command-and-controlpayload-developmentpersistence-mechanisms+6
60310 months ago
CVE-2026-31431 preview

CVE-2026-31431

GitHubhulnothutu/cve-2026-31431

对 CVE-2026-31431 的复现分析、C 改编的 exp。

binary-exploitationcontainer-escapeeducation+6
3 months ago
ingressNightmare-CVE-2025-1974-exps preview

ingressNightmare-CVE-2025-1974-exps

GitHubesonhugh/ingressnightmare-cve-2025-1974-exps

IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation.…

cloud-securitycontainer-securityexploitation+5
981 year ago
IngressNightterror preview

IngressNightterror

GitHubi3r1h0n/ingressnightterror

My view on IngressNightmare vulnerability (CVE-2025-1974)

cloud-securitycontainer-securityeducation+5
110 months ago
FiberBreak preview

FiberBreak

GitHubscumfrog/fiberbreak

React2Shell Exploitation Tool (CVE-2025-55182)

cloud-securitycommand-and-controldata-exfiltration+8
8 months ago
CVE-2026-31431 preview

CVE-2026-31431

GitHubjuanbindez/cve-2026-31431

Copy Fail - CVE-2026-31431

binary-exploitationexploitationmemory-forensics+4
213 months ago
CVE-2026-24207 preview

CVE-2026-24207

GitHuboffseckit/cve-2026-24207

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

authenticationcloud-securitycommand-and-control+8
12 months ago
CocoaPods-RCE_CVE-2024-38366 preview

CocoaPods-RCE_CVE-2024-38366

GitHubreefspek/cocoapods-rce_cve-2024-38366

CocoaPods RCE Vulnerability CVE-2024-38366

command-and-controlexploitationpayload-development+5
12 years ago
Previous12Next