Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
THM---Solar-exploiting-Log-4j preview

THM---Solar-exploiting-Log-4j

GitHubsaru1718/thm---solar-exploiting-log-4j

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

educationexploitationids-ips-evasion+7
5 months ago
shadow-workers preview

shadow-workers

GitHubshadow-workers/shadow-workers

Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service…

command-and-controlpenetration-testingpersistence-mechanisms+2
2462 years ago
POC-of-CVE-2022-36271 preview

POC-of-CVE-2022-36271

GitHubsaumyajeetdas/poc-of-cve-2022-36271

This is working POC of CVE-2022-36271

binary-exploitationexploitationmalware-analysis+3
94 years ago
CVE-2025-54914-PoC preview

CVE-2025-54914-PoC

GitHubash1996x/cve-2025-54914-poc

Exploit for CVE-2025-54914 in Azure Networking, creating malicious routes with evasion, persistence, multi-target scanning, and reporting for…

cloud-securityexploitationids-ips-evasion+4
411 months ago
CVE-2024-36842-Backdooring-Oncord-Android-Sterio- preview

CVE-2024-36842-Backdooring-Oncord-Android-Sterio-

GitHubabbiy/cve-2024-36842-backdooring-oncord-android-sterio-

CVE-2024-36842, Creating Persistent Backdoor on Oncord+ android/ios car infotaiment using malicious script!

android-securityembedded-systems-securityexploitation+5
51 year ago
PowerLurk preview

PowerLurk

GitHubsw4mpf0x/powerlurk

Malicious WMI Events using PowerShell

information-gatheringpayload-generationpenetration-testing+5
39810 years ago
dll-proxy-generator preview

dll-proxy-generator

GitHubnamazso/dll-proxy-generator

Generate a proxy dll for arbitrary dll

binary-analysispayload-generationpersistence-mechanisms+3
2491 year ago
rustdllproxy preview

rustdllproxy

GitHubjohnswiftc/rustdllproxy

Generate Proxy DLLs in Rust

payload-developmentpayload-generationpenetration-testing+3
572 months ago
ForgeCert preview

ForgeCert

GitHubghostpack/forgecert

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

authenticationexploitationpayload-generation+1
7153 years ago
DogWalk-rce-poc preview

DogWalk-rce-poc

GitHubariary/dogwalk-rce-poc

🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)

exploitationpayload-generationpenetration-testing+1
764 years ago
Powershell-C2 preview

Powershell-C2

GitHubenigma0x3/powershell-c2

PowerShell-based command and control framework using website-hosted payloads for persistent remote access and post-exploitation on Windows systems.

command-and-controlpayload-generationpenetration-testing+3
5012 years ago
PIRATE preview

PIRATE

GitHubgbrn1/pirate

Python Remote Access Tool

command-and-controlpayload-generationpenetration-testing+5
266 years ago
CVE-2025-56799 preview

CVE-2025-56799

GitHubshinycolumn/cve-2025-56799

OS Command Injection Vulnerability via Cache Clearing Scheduler in Reolink Desktop Application

binary-exploitationexploitationmalware-analysis+3
110 months ago
sAINT preview
Archived

sAINT

GitHubtiagorlampert/saint

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

data-exfiltrationpayload-generationpersistence-mechanisms+1
7556 years ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

adversarial-attackcommand-and-controleducation+9
1.1k7 days ago
ElfDoor-gcc preview

ElfDoor-gcc

GitHubmatheuzsecurity/elfdoor-gcc

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

binary-exploitationpersistence-mechanismssupply-chain-security
1331 year ago
SkillsGuard preview

SkillsGuard

GitHubteycir/skillsguard

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

ai-securitycode-analysiscommand-and-control+8
152 months ago
WinRAR-CVE-2025-8088-Exploitation-Toolkit preview

WinRAR-CVE-2025-8088-Exploitation-Toolkit

GitHubxi0onamdev/winrar-cve-2025-8088-exploitation-toolkit

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…

binary-exploitationeducationexploitation+7
9 months ago
Previous123Next