Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
khaos-c2 preview

khaos-c2

GitHub28zaaky/khaos-c2

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

command-and-controllateral-movementpayload-development+5
238
4 days ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
1945 days ago
PrintSpoofer-ReflectiveDLL preview

PrintSpoofer-ReflectiveDLL

GitHubjonyfilc/printspoofer-reflectivedll

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

exploitationlateral-movementpayload-development+4
21 month ago
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
1 month ago
tgt-monitor-bof preview

tgt-monitor-bof

GitHubjakobfriedl/tgt-monitor-bof

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

authenticationlateral-movementpayload-development+3
1351 month ago
CVE-2026-58635-PoC preview

CVE-2026-58635-PoC

GitHubdavidcarliez/cve-2026-58635-poc

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

binary-exploitationcommand-and-controlexploitation+5
302 months ago
DCOMIllusionist preview

DCOMIllusionist

GitHubsynacktiv/dcomillusionist

DCOM in memory and fileless lateral movement techniques through .Net deserilization

authenticationcommand-and-controlexploitation+7
2932 months ago
DSCourier_BOF preview

DSCourier_BOF

GitHuboctoberfest7/dscourier_bof

BOF POC of the DSCourier project / invoking WinGet via COM

command-and-controlexploitationlateral-movement+5
904 months ago
RedTeam-Tools preview

RedTeam-Tools

GitHuba-poc/redteam-tools

Tools and Techniques for Red Team / Penetration Testing

exploitationlateral-movementosint+7
9.7k5 months ago
CVE-2021-21220 preview

CVE-2021-21220

GitHubjacobtaylor3/cve-2021-21220

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.

command-and-controlexploitationlateral-movement+5
5 months ago
FortiLPE preview

FortiLPE

GitHubspaceplant/fortilpe

Local privilege escalation exploit for CVE-2025-62676.

binary-exploitationexploitationlateral-movement+4
46 months ago
ColdWer preview

ColdWer

GitHub0xsh3llf1r3/coldwer

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

exploitationlateral-movementpayload-development+3
1467 months ago
ZeroPulse preview

ZeroPulse

GitHubjxroot/zeropulse

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

command-and-controlexploitationlateral-movement+8
1448 months ago
Blackash-CVE-2025-33073 preview

Blackash-CVE-2025-33073

GitHubirjfifndn-prog/blackash-cve-2025-33073

CVE-2025-33073

command-and-controlexploitationlateral-movement+4
10 months ago
CVE-2025-52136 preview

CVE-2025-52136

GitHubf1r3k0/cve-2025-52136

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

command-and-controlexploitationlateral-movement+3
511 months ago
CVE-2025-50505 preview

CVE-2025-50505

GitHuba0yami/cve-2025-50505

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

command-and-controldns-analysisexploitation+8
2011 months ago
LdrShuffle preview

LdrShuffle

GitHubrwxstoned/ldrshuffle

Code execution/injection technique using DLL PEB module structure manipulation

binary-exploitationcode-analysisexploitation+6
2871 year ago
CVE-2024-57394 preview

CVE-2024-57394

GitHubcwjchoi01/cve-2024-57394

Proof-of-concept exploit for CVE-2024-57394: low-privilege file restoration to System32 enabling DLL hijacking and local privilege escalation to…

binary-exploitationexploitationlateral-movement+4
1 year ago
Previous123Next