Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
12.0k4 days ago
ghostlock-s26 preview

ghostlock-s26

GitHub1ndevelopment/ghostlock-s26

GhostLock (CVE-2026-43499) app for the Galaxy S26 series

android-securityexploitationmobile-app-pentesting+5
1015 days ago
CVE-2026-78006-POC preview

CVE-2026-78006-POC

GitHubdeadexpl0it/cve-2026-78006-poc

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

defensive-toolsexploitationpayload-development+7
428 days ago
APatch preview

APatch

GitHubbmax121/apatch

The patching of Android kernel and Android system

android-securitymobile-securitypayload-development+4
8.0k6h 56m ago
FolkPatch preview

FolkPatch

GitHublyravoid/folkpatch

Root access to the kernel can be achieved simply by patching the Boot partition for reflashing. This solution is based on a non-parallel extended…

android-securitymobile-securitypayload-development+3
1.2k4 days ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
39.1k2 days ago
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

cloud-securitycurated-resourceseducation+8
363 months ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

cloud-securitycommand-and-controlencryption-decryption-tools+6
431 month ago
ghostlock-s26 preview

ghostlock-s26

GitHubsnothin/ghostlock-s26

GhostLock (CVE-2026-43499) for the Galaxy S26

android-securitybinary-exploitationexploitation+5
1810 days ago
mimikatz preview

mimikatz

GitHubgentilkiwi/mimikatz

A little tool to play with Windows security

authenticationexploitationexploit-frameworks+10
21.9k5 months ago
TornadoRevC2 preview

TornadoRevC2

GitHubkamalx06/tornadorevc2

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

command-and-controlinformation-gatheringlateral-movement+8
343 days ago
moukthar preview

moukthar

GitHubtomiwa-ot/moukthar

Android remote administration tool

android-securitycommand-and-controldata-exfiltration+6
68311 months ago
lockjaw preview

lockjaw

GitHubg13net/lockjaw

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

command-and-controldns-analysisexploit-frameworks+9
3010 days ago
impacket preview

impacket

GitHubfortra/impacket

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

authenticationcommand-and-controldatabase-security+17
16.2k9 days ago
TLPE preview

TLPE

GitHubsupersonic/tlpe

CVE-2026-49881, using insecure context creation in Android 17's Telecom service to execute arbitrary code as UID 1000 system_server from an…

android-securitybinary-exploitationexploitation+4
1031 month ago
ghostlock-a17 preview

ghostlock-a17

GitHubmobilehackinglab/ghostlock-a17

Kernel exploit for CVE-2026-43499 on Samsung Galaxy A17 achieving root via KDP bypass, KASLR recovery, and forged workqueue execution with persistent…

android-securitybinary-exploitationexploitation+4
151 month ago
MMSkillRisk preview

MMSkillRisk

GitHubkaill-jlq/mmskillrisk

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

adversarial-attackai-securitydata-exfiltration+7
610 days ago
iOS18.6.2-Persistent-Automation-Exploit-in-Siri-Shortcuts-and-Apple-SWC preview

iOS18.6.2-Persistent-Automation-Exploit-in-Siri-Shortcuts-and-Apple-SWC

GitHubjgoyd/ios18.6.2-persistent-automation-exploit-in-siri-shortcuts-and-apple-swc

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

exploitationios-securitylateral-movement+4
176 months ago
Previous1234Next