Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1834 results
CVE-2026-58424 preview

CVE-2026-58424

GitHubbridgeralderson/cve-2026-58424

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

authentication-authorizationexploitationpayload-development+4
2
1 month ago
chamilo-lms-unauthenticated-big-upload-rce-poc preview

chamilo-lms-unauthenticated-big-upload-rce-poc

GitHubm3m0o/chamilo-lms-unauthenticated-big-upload-rce-poc

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

exploitationpayload-developmentpenetration-testing+3
2 years ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2986 months ago
Aladdin preview

Aladdin

GitHubnettitude/aladdin

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

exploitationpayload-developmentpayload-generation+1
2252 years ago
bt2 preview

bt2

GitHubblazeinfosec/bt2

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

command-and-controlpayload-developmentpenetration-testing+3
20610 years ago
RansomLord preview

RansomLord

GitHubmalvuln/ransomlord

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

binary-exploitationdefensive-toolsexploitation+4
5161 year ago
msf-remote-console preview
Archived

msf-remote-console

GitHubqubasa/msf-remote-console

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

command-and-controlexploit-frameworkspayload-development+3
577 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubmaximofernandezriera/cve-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

exploitationpayload-developmentpenetration-testing+2
54 years ago
CVE-2021-44228-Apache-Log4j-Rce preview

CVE-2021-44228-Apache-Log4j-Rce

GitHubkannthu/cve-2021-44228-apache-log4j-rce

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection payloads, WAF bypass techniques, and passive scanning integration for…

exploitationpayload-developmentpenetration-testing+3
4 years ago
Exch-CVE-2021-26855 preview
Archived

Exch-CVE-2021-26855

GitHubzephrfish/exch-cve-2021-26855

CVE-2021-26855: PoC (Not a HoneyPoC for once!)

exploitationpayload-developmentpenetration-testing+2
301 month ago
TheFatRat preview

TheFatRat

GitHubscreetsec/thefatrat

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

educationexploit-frameworksmalware-analysis+4
11.5k4 years ago
nanodump preview

nanodump

GitHubfortra/nanodump

The swiss army knife of LSASS dumping

exploitationmemory-forensicspayload-development+4
2.1k1 year ago
CVE-2025-24076 preview

CVE-2025-24076

GitHubmbanyamer/cve-2025-24076

Python exploit for CVE-2025-24076, a Windows Cross Device Service privilege escalation vulnerability. Replaces a DLL to achieve SYSTEM privileges via…

binary-exploitationeducationexploitation+3
201 year ago
cve-2016-7190 preview

cve-2016-7190

GitHub0xcl/cve-2016-7190

ChakraCore exploitation techniques

binary-exploitationeducationexploitation+5
98 years ago
WinRAR-CVE-2025-8088-Path-Traversal-PoC preview

WinRAR-CVE-2025-8088-Path-Traversal-PoC

GitHubpexlexity/winrar-cve-2025-8088-path-traversal-poc

Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)

binary-exploitationexploitationmalware-analysis+3
21 year ago
CVE-2025-6218-WinRAR-Directory-Traversal-RCE preview

CVE-2025-6218-WinRAR-Directory-Traversal-RCE

GitHubabsholi7ly/cve-2025-6218-winrar-directory-traversal-rce

CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction directory when…

binary-exploitationexploitationpayload-development+3
191 year ago
pixel-ksu-root preview

pixel-ksu-root

GitHubjingmatrix/pixel-ksu-root

adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched…

android-securityexploitationexploit-frameworks+6
137 days ago
CVE-2024-43044-jenkins preview

CVE-2024-43044-jenkins

GitHubconvisolabs/cve-2024-43044-jenkins

Exploit for the vulnerability CVE-2024-43044 in Jenkins

exploitationpayload-developmentpenetration-testing+3
1852 years ago
Previous123…100Next