Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
143 results
DNSRPC-BOF preview

DNSRPC-BOF

GitHubparadoxis/dnsrpc-bof

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

exploitationpayload-developmentpenetration-testing+2
50
1 month ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
3 months ago
cPanelSniper preview

cPanelSniper

GitHubynsmroztas/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4944 months ago
blankspace preview

blankspace

GitHubjbaines-r7/blankspace

Proof of Concept for EFSRPC Arbitrary File Upload (CVE-2021-43893)

exploitationexploit-frameworkslateral-movement+2
644 years ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubalhakim88/cve-2026-21858

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

exploitationpayload-developmentpenetration-testing+4
7 months ago
CVE-2026-65400 preview

CVE-2026-65400

GitHubacheong08/cve-2026-65400

Apple MacOS Screen Sharing Arbitrary File read/write -> RCE

data-exfiltrationexploitationpenetration-testing+3
28 days ago
CVE-2026-65400 preview

CVE-2026-65400

GitHubhorkimhab/cve-2026-65400

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

authenticationeducationexploitation+4
312 days ago
chyrp-lite-rce-poc preview

chyrp-lite-rce-poc

GitHubiltosec/chyrp-lite-rce-poc

CVE-2026-53767 + CVE-2026-53768 - Authenticated RCE in Chyrp Lite ≤ 2026.01 via uploads_path blocklist bypass and missing extension validation

educationexploitationpayload-development+4
2 months ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
19 days ago
cs-token-vault preview

cs-token-vault

GitHubhenkru/cs-token-vault

In-memory token vault BOF for Cobalt Strike

authentication-authorizationpenetration-testing-frameworkspost-exploitation+2
1514 years ago
NiCOFF preview

NiCOFF

GitHubfrkngksl/nicoff

COFF and BOF Loader written in Nim

payload-developmentpenetration-testingpost-exploitation+1
1774 months ago
ContextMenuHijack preview

ContextMenuHijack

GitHubristbs/contextmenuhijack

Execute a payload at each right click on a file/folder in the explorer menu for persistence

payload-developmentpersistence-mechanismspost-exploitation+1
1733 years ago
amd-ryzen-master-driver-v17-exploit preview

amd-ryzen-master-driver-v17-exploit

GitHubtijme/amd-ryzen-master-driver-v17-exploit

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

binary-exploitationexploitationexploit-frameworks+4
1603 years ago
Elevate-System-Trusted-BOF preview

Elevate-System-Trusted-BOF

GitHubmr-un1k0d3r/elevate-system-trusted-bof

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

command-and-controlpayload-developmentpost-exploitation+2
1813 years ago
OwnershipStealer preview

OwnershipStealer

GitHubadpunisher/ownershipstealer

Command-line utility for Windows that enables SeTakeOwnershipPrivilege and modifies file ownership to the current user, granting access to otherwise…

adversarial-attackpenetration-testingpost-exploitation+2
283 years ago
secretsdump.py preview

secretsdump.py

GitHubfin3ss3g0d/secretsdump.py

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

data-exfiltrationpassword-attackspenetration-testing+2
2593 years ago
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

OSWE, OSEP, OSED, OSEE

binary-exploitationcurated-resourceseducation+9
3.9k7 months ago
No-Consolation preview

No-Consolation

GitHubfortra/no-consolation

A BOF that runs unmanaged PEs inline

ids-ips-evasionpayload-developmentpenetration-testing-frameworks+2
7021 year ago
Previous12…8Next