Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
meterssh preview

meterssh

GitHubtrustedsec/meterssh

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

command-and-controlexploitationpayload-development+4
530
9 years ago
LibTP_Gadget preview

LibTP_Gadget

GitHubsaerxcit/libtp_gadget

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

adversarial-attackids-ips-evasionpayload-development+3
2310 months ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
91 month ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
2101 month ago
CVE-2023-38545 preview

CVE-2023-38545

GitHubd0rb/cve-2023-38545

This script is designed to exploit a heap buffer overflow vulnerability in a socks5 proxy server.

exploitationpayload-developmentpenetration-testing+3
212 years ago
CVE-2024-0311 preview

CVE-2024-0311

GitHubcalligraf0/cve-2024-0311

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

binary-exploitationexploitationids-ips-evasion+4
91 year ago
Project-CVE-2026-75604 preview

Project-CVE-2026-75604

GitHube4zyy/project-cve-2026-75604

Python-based exploitation framework for CVE-2026-75604, enabling authorized pentesters to validate Next.js Windows cache traversal vulnerabilities…

exploitationpayload-developmentpenetration-testing+4
216 days ago
CVE-2025-69985 preview

CVE-2025-69985

GitHubkaleth4/cve-2025-69985

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…

authentication-authorizationexploitationpayload-development+5
4 months ago
CVE-2024-44625-Gogs-RCE-0.13.0 preview

CVE-2024-44625-Gogs-RCE-0.13.0

GitHubbatj44/cve-2024-44625-gogs-rce-0.13.0

Exploit for CVE-2024-44625 in Gogs 0.13.0, achieving remote code execution via symlink-follow to create a git hook, with reverse and bind shell modes.

exploitationpayload-developmentpenetration-testing+3
3 days ago
CVE-2024-2053 preview

CVE-2024-2053

GitHubb-l-x/cve-2024-2053

CVE-2024-2053

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2026-43499-S26 preview

CVE-2026-43499-S26

GitHubsammyenigma/cve-2026-43499-s26

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

android-securitybinary-exploitationexploitation+8
23 days ago
DLLirant preview

DLLirant

GitHubredteamsocietegenerale/dllirant

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

binary-analysisdynamic-code-analysisexploitation+3
5033 years ago
ExportHider preview

ExportHider

GitHubfrkngksl/exporthider

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

binary-analysisdynamic-code-analysisexploitation+4
335 months ago
CVE-2025-59528-PoC preview

CVE-2025-59528-PoC

GitHubloaxert/cve-2025-59528-poc

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

api-security-testingeducationexploitation+3
1 month ago
CVE-2021-30853 preview

CVE-2021-30853

GitHubshubham0d/cve-2021-30853

Proof-of-concept script that demonstrates bypassing macOS Gatekeeper, notarization, and XProtect checks by exploiting CVE-2021-30853, allowing…

exploitationpayload-developmentweb-application-exploitation
24 years ago
java-stager preview

java-stager

GitHubcornerpirate/java-stager

A PoC Java Stager which can download, compile, and execute a Java file in memory.

command-and-controldynamic-code-analysiseducation+7
1078 years ago
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

dynamic-code-analysiseducationencryption-decryption-tools+7
472 months ago
CVE-2019-11708 preview
Archived

CVE-2019-11708

GitHub0vercl0k/cve-2019-11708

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

exploitationpayload-developmentweb-application-exploitation
6246 years ago
Previous123Next