Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
BadSamba preview

BadSamba

GitHubstrozfriedberg/badsamba

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

exploitationlateral-movementnetwork-security+3
22
6 years ago
CVE-2018-20250-poc-winrar preview

CVE-2018-20250-poc-winrar

GitHubnmweizi/cve-2018-20250-poc-winrar

Proof-of-concept exploit for CVE-2018-20250, a remote code execution vulnerability in WinRAR's ACE file extraction, enabling arbitrary file write to…

binary-exploitationexploitationpayload-development+2
7 years ago
CVE-2018-14699 preview

CVE-2018-14699

GitHubrevocain/cve-2018-14699

Unauthenticated Blind Command injection in the enable_user function of DroboAccess v 2.1

command-and-controlexploitationpayload-generation+3
14 years ago
sectemplates preview

sectemplates

GitHubsecuritytemplates/sectemplates

Open source templates you can use to bootstrap your security programs

configuration-auditingcurated-resourceseducation+3
9161 month ago
rpc2wc preview

rpc2wc

GitHub0xthirteen/rpc2wc

PoC that triggers Windows WebClient startup through EFS RPC call chains and WNF messages, enabling red teams to explore unprivileged service-start…

exploitationpenetration-testingpost-exploitation+1
601 year ago
CVE-2018-20250 preview

CVE-2018-20250

GitHublikekabin/cve-2018-20250

Python exploit script for CVE-2018-20250 that generates a malicious RAR archive to achieve code execution via WinRAR's ACE file extraction…

exploitationpayload-generationpenetration-testing+2
7 years ago
WinRAR-CVE-2025-8088-Exploitation-Toolkit preview

WinRAR-CVE-2025-8088-Exploitation-Toolkit

GitHubxi0onamdev/winrar-cve-2025-8088-exploitation-toolkit

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…

binary-exploitationeducationexploitation+7
9 months ago
CVE-2018-20250 preview

CVE-2018-20250

GitHubtzwlhack/cve-2018-20250

Automated exploit script for CVE-2018-20250 (WinRAR ACE extraction code execution) that generates a malicious archive file embedding a payload into…

exploitationpayload-generationpenetration-testing+3
4 years ago
CVE-2025-4606 preview

CVE-2025-4606

GitHubyetazyyy/cve-2025-4606

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

educationexploitationpenetration-testing+3
6 months ago
CVE-2025-59536 preview

CVE-2025-59536

GitHubnetvanguard-cmd/cve-2025-59536

PoC exploit for CVE-2025-59536, a high-severity code injection vulnerability in Claude Code's startup trust dialog, enabling remote exploitation of…

code-analysisexploitationpenetration-testing+2
5 months ago
SharPersist preview
Archived

SharPersist

GitHubmandiant/sharpersist

C# toolkit for establishing and managing Windows persistence via registry keys, scheduled tasks, services, startup folders, KeePass configs, and…

penetration-testingpersistence-mechanismspost-exploitation+1
1.5k3 years ago
CVE-2021-42559 preview

CVE-2021-42559

GitHubmbadanoiu/cve-2021-42559

CVE-2021-42559: Command Injection via Configurations in MITRE Caldera

command-and-controlexploitationpenetration-testing+3
2 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5444 years ago
p3-loader preview

p3-loader

GitHuborange-cyberdefense/p3-loader

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

binary-exploitationdefensive-toolseducation+8
2132 months ago