Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1639 results
CVE-2019-11043 preview

CVE-2019-11043

GitHubthemiddleblue/cve-2019-11043

(PoC) Python version of CVE-2019-11043 exploit by neex

exploitationpayload-developmentpenetration-testing+3
147
6 years ago
CVE-2017-0781 preview

CVE-2017-0781

GitHubojasookert/cve-2017-0781

Blueborne CVE-2017-0781 Android heap overflow vulnerability

android-securitybinary-exploitationbluetooth-security+6
1385 years ago
BlueSAM preview

BlueSAM

GitHubincursi0n/bluesam

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

command-and-controlexploitationpayload-development+3
1675 months ago
ProxyVulns preview

ProxyVulns

GitHubhosch3n/proxyvulns

[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains.…

exploitationexploit-frameworkspayload-development+3
1743 years ago
whatsapp-mitd-mitm preview

whatsapp-mitd-mitm

GitHubcensus/whatsapp-mitd-mitm

PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)

android-securityexploitationmobile-security+3
1495 years ago
initroot preview

initroot

GitHubalephsecurity/initroot

Motorola Untethered Jailbreak: Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass

android-securitybinary-exploitationexploitation+5
839 years ago
cve-2017-7269 preview

cve-2017-7269

GitHubzcgonvh/cve-2017-7269

fixed msf module for cve-2017-7269

exploitationexploit-frameworkspayload-development+3
1359 years ago
threadfire preview

threadfire

GitHubjosh0xa/threadfire

PoC Thread Execution Hijacking for Win32 Code Injection

payload-developmentpenetration-testingred-teaming+1
1742 years ago
XSS-Payloads preview

XSS-Payloads

GitHuborwagodfather/xss-payloads
payload-developmentpenetration-testingvulnerability-analysis+2
2008 months ago
CLR-Unhook preview

CLR-Unhook

GitHubhwbp/clr-unhook

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

defensive-toolsexploitationpayload-development+3
2149 months ago
VeeamDumper-BOF preview

VeeamDumper-BOF

GitHubmwr-cybersec/veeamdumper-bof

A credential extraction BOF for Veeam Backup and Replication and Veeam One

password-attackspayload-developmentpenetration-testing+2
803 days ago
aggrokatz preview

aggrokatz

GitHubsec-consult/aggrokatz

Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse…

exploit-frameworkspayload-developmentpenetration-testing+2
1545 years ago
CVE-2024-4577-PHP-RCE preview

CVE-2024-4577-PHP-RCE

GitHubxcanwin/cve-2024-4577-php-rce

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。

exploitationpayload-developmentpenetration-testing+3
1622 years ago
CVE-2024-27956-RCE preview

CVE-2024-27956-RCE

GitHubdiego-tella/cve-2024-27956-rce

PoC for SQL Injection in CVE-2024-27956

exploitationpayload-developmentpenetration-testing+2
902 years ago
tap-ducky preview

tap-ducky

GitHubiodn/tap-ducky

Turns any rooted phone into the legendary USB Rubber Ducky. Android USB HID Keystroke Injector

android-securityexploitationhardware-hacking+5
1714 months ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubricseclab/cve-2019-0708

CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7

binary-exploitationexploitationpayload-development+3
1494 years ago
CVE-2020-15778 preview

CVE-2020-15778

GitHubcpandya2909/cve-2020-15778

Technical write-up and proof-of-concept for CVE-2020-15778, an authenticated command injection vulnerability in OpenSSH scp (<=8.3p1) allowing remote…

command-and-controlexploitationpayload-development+3
1423 years ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1602 years ago
Previous1…111213…92Next