Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3645 results
njutils preview

njutils

GitHubseep1959/njutils

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

command-and-controlpayload-developmentpenetration-testing+3
78 years ago
CVE-2026-3228 preview

CVE-2026-3228

GitHubnull200ok/cve-2026-3228

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

exploitationpayload-developmentpenetration-testing+3
26 months ago
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
21 month ago
Red-Teaming-Toolkit preview

Red-Teaming-Toolkit

GitHubinfosecn1nja/red-teaming-toolkit

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

command-and-controlcurated-resourceslateral-movement+6
10.7k4 months ago
DuplexSpyCS preview

DuplexSpyCS

GitHubiss4cf0ng/duplexspycs

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

command-and-controleducationpayload-development+5
2236 months ago
CVE-2026-25938-FUXA-Unauthenticated-RCE preview

CVE-2026-25938-FUXA-Unauthenticated-RCE

GitHubjudgedbykira/cve-2026-25938-fuxa-unauthenticated-rce

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

exploitationiot-securitypayload-development+6
11 month ago
tap-ducky preview

tap-ducky

GitHubiodn/tap-ducky

Turns any rooted phone into the legendary USB Rubber Ducky. Android USB HID Keystroke Injector

android-securityexploitationhardware-hacking+5
1744 months ago
Ninja preview

Ninja

GitHubahmedkhlief/ninja

Open source C2 server created for stealth red team operations

command-and-controlexploitationinformation-gathering+6
8403 years ago
CVE-2026-22241 preview

CVE-2026-22241

GitHubashifcoder/cve-2026-22241

Automated exploit for CVE-2026-22241, an unrestricted file upload vulnerability in Open eClass, enabling remote code execution via a webshell with…

exploitationpayload-developmentpenetration-testing+3
18 months ago
siemframework preview

siemframework

GitHubelevenpaths/siemframework

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

exploit-frameworksinformation-gatheringnetwork-mapping+7
426 years ago
Chankro preview

Chankro

GitHubtarlogicsecurity/chankro

Herramienta para evadir disable_functions y open_basedir

exploitationpayload-developmentpenetration-testing+3
4957 years ago
SharpKiller preview

SharpKiller

GitHubs1lkys/sharpkiller

Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8

exploitationids-ips-evasionpayload-development+3
3472 years ago
toastnotify-bof preview

toastnotify-bof

GitHubbrmkit/toastnotify-bof

abusing windows toast notifications for fun and user manipulation

information-gatheringpayload-developmentphishing+3
1052 months ago
CVE-2026-58424 preview

CVE-2026-58424

GitHubbridgeralderson/cve-2026-58424

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

authentication-authorizationexploitationpayload-development+4
21 month ago
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
2 months ago
cve-2026-41940-tool preview

cve-2026-41940-tool

GitHubnull200ok/cve-2026-41940-tool

A comprehensive Python utility to **detect**, **scan in bulk**, and **exploit** the critical authentication bypass vulnerability (CVE-2026-41940) in…

exploitationinformation-gatheringpayload-development+5
44 months ago
trellix-tarslip-patch-bypass preview

trellix-tarslip-patch-bypass

GitHubluigigubello/trellix-tarslip-patch-bypass

Proof-of-concept bypass for CVE-2007-4559 path traversal vulnerability in Trellix's patch, demonstrating symlink-based exploitation technique.

exploitationpayload-developmentpenetration-testing+2
2 years ago
byvalver preview

byvalver

GitHubumpolungfish/byvalver

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

binary-analysisexploitationmachine-learning+6
626 months ago
Previous123…100Next