Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
360 results
CVE-2021-42362 preview

CVE-2021-42362

GitHubsamiba6/cve-2021-42362

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the…

exploitationpayload-developmentremote-access-tool+2
1 year ago
Elevate-System-Trusted-BOF preview

Elevate-System-Trusted-BOF

GitHubmr-un1k0d3r/elevate-system-trusted-bof

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

command-and-controlpayload-developmentpost-exploitation+2
1813 years ago
SigFlip preview

SigFlip

GitHubmed0x2e/sigflip

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

binary-analysiscode-analysisdefensive-tools+5
1.3k3 years ago
CVE-2019-11932-SupportApp preview

CVE-2019-11932-SupportApp

GitHubvalbrux/cve-2019-11932-supportapp

This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address…

android-securitybinary-exploitationexploitation+3
386 years ago
CVE-2018-17246 preview

CVE-2018-17246

GitHubmpgn/cve-2018-17246

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

exploitationpayload-developmentpenetration-testing+3
656 years ago
cve-2023-5966 preview

cve-2023-5966

GitHubll104567/cve-2023-5966

Proof-of-concept exploit for CVE-2023-5966, an arbitrary file upload vulnerability in EspoCRM 2.7.4 and earlier, enabling remote code execution via a…

exploitationpayload-developmentpenetration-testing+2
2 years ago
CVE-2023-50164-Apache-Struts-RCE preview

CVE-2023-50164-Apache-Struts-RCE

GitHubjakabakos/cve-2023-50164-apache-struts-rce

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload…

educationexploitationpayload-development+3
8610 months ago
CVE-2024-53677-S2-067 preview

CVE-2024-53677-S2-067

GitHubtam-k592/cve-2024-53677-s2-067

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

exploitationpayload-developmentpenetration-testing+3
961 year ago
ExtensionSpoofer preview

ExtensionSpoofer

GitHubhenriksb/extensionspoofer

Spoof file icons and extensions in Windows

ids-ips-evasionimpersonation-toolsmalware-analysis+3
18724 days ago
CVE-2020-25042-PoC preview

CVE-2020-25042-PoC

GitHubgroppoxx/cve-2020-25042-poc

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

exploitationpayload-developmentpenetration-testing+3
53 months ago
CVE-2019-16278_Nostromo-1.9.6---Remote-Code-Execution preview

CVE-2019-16278_Nostromo-1.9.6---Remote-Code-Execution

GitHubcybermonkx/cve-2019-16278_nostromo-1.9.6---remote-code-execution

An unauthenticated attacker can force server points to a shell file like ‘/bin/sh’ and execute arbitrary commands due to the failure in verifying the…

exploitationpayload-developmentpenetration-testing+3
1 year ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2986 months ago
CVE-2025-53547-POC preview

CVE-2025-53547-POC

GitHubdvkunion/cve-2025-53547-poc

CVE-2025-53547 one of poc code

command-and-controlexploitationpayload-development+2
91 year ago
Shellcrypt preview

Shellcrypt

GitHubiilegacyyii/shellcrypt

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

cryptographyencryption-decryption-toolspayload-development+3
2173 years ago
PackMyPayload preview

PackMyPayload

GitHubmgeeky/packmypayload

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

container-securityexploit-frameworkspayload-development+3
1.2k2 years ago
-EXPLOIT-CVE-2023-36025 preview

-EXPLOIT-CVE-2023-36025

GitHubcoolman6942o/-exploit-cve-2023-36025

Windows SmartScreen Security Feature Bypass Vulnerability

command-and-controlexploitationexploit-frameworks+2
52 years ago
BobTheSmuggler preview

BobTheSmuggler

GitHubthecyb3ralpha/bobthesmuggler

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

educationencryption-decryption-toolspayload-development+4
60010 months ago
BiblioRCE preview

BiblioRCE

GitHubexopteron/bibliorce

CVE-2023-29478 - BiblioCraft File Manipulation/Remote Code Execution exploit affecting BiblioCraft versions prior to v2.4.6

binary-exploitationexploitationpayload-development+5
142 years ago
Previous12…20Next