Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
660 results
Certi-Bhai preview

Certi-Bhai

GitHubincredibleindishell/certi-bhai

AD CS exploitation related stuff goes here

authenticationexploitationpayload-generation+4
26
5 months ago
ReflectiveDLLInjection preview

ReflectiveDLLInjection

GitHubstephenfewer/reflectivedllinjection

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

exploitationmemory-forensicspayload-development+2
3.3k4 years ago
PrettyPrague preview

PrettyPrague

GitHubmsnightmare/prettyprague

GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability

exploitationexploit-frameworkspayload-development+3
507 days ago
tfo-connect-bypass preview

tfo-connect-bypass

GitHub4n4s4zi/tfo-connect-bypass

Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)

exploitationids-ips-evasionnetwork-security+3
4 days ago
CS-DropSpawn_BOF preview

CS-DropSpawn_BOF

GitHubgmh5225/cs-dropspawn_bof

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

exploitationpayload-developmentpenetration-testing+2
23 years ago
RedTeamScripts preview

RedTeamScripts

GitHubmr-un1k0d3r/redteamscripts

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

email-securityexploitationpassword-attacks+4
1475 years ago
Atlas preview

Atlas

GitHubportbuster1337/atlas

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

exploitationlateral-movementnetwork-security+4
555 days ago
electroniz3r preview

electroniz3r

GitHubr3ggi/electroniz3r

Take over macOS Electron apps' TCC permissions

exploitationpost-exploitationprivilege-escalation+1
2243 years ago
DNSRPC-BOF preview

DNSRPC-BOF

GitHubparadoxis/dnsrpc-bof

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

exploitationpayload-developmentpenetration-testing+2
562 months ago
hacktivity-vulns-exploits-lab preview

hacktivity-vulns-exploits-lab

GitHubocfagb/hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit,…

educationexploitationlabs-practice+5
10 days ago
hayduk preview

hayduk

GitHubjolovicdev/hayduk

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

exploit-frameworksnetwork-mappingpenetration-testing-frameworks+3
26 days ago
CVE-2026-31431 preview

CVE-2026-31431

GitHubmalwarekid/cve-2026-31431

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel AF_ALG memory corruption vulnerability. Uses splice to patch /usr/bin/su in page cache,…

binary-exploitationexploitationexploit-frameworks+3
94 months ago
CVE-2026-0073 preview

CVE-2026-0073

GitHubdevtint/cve-2026-0073

Weaponized proof-of-concept for CVE-2026-0073, an Android adbd authentication bypass enabling zero-click remote root access via Wireless ADB, with…

android-securityexploitationmobile-security+5
44 months ago
CVE-2026-31431-REVSHELL preview

CVE-2026-31431-REVSHELL

GitHubdanimrtzp/cve-2026-31431-revshell

Weaponized Python exploit for CVE-2026-31431, chaining Linux kernel privilege escalation to a daemonized root reverse shell with full PTY, patching…

exploitationexploit-frameworkspayload-development+5
4 months ago
UnrestrictedUserCreator preview

UnrestrictedUserCreator

GitHubrifting/unrestrictedusercreator

Simple script to add a new, unrestricted user on devices with Family Link by abusing CVE-2025-32324 (pre September patch)

android-securityexploitationmobile-security+2
410 months ago
RegPwnBRc4BOF preview

RegPwnBRc4BOF

GitHubn0isegat3/regpwnbrc4bof

Brute Ratel C4 BOF that exploits a registry symlink race condition in Windows Accessibility ATConfig to escalate privileges to SYSTEM by writing…

binary-exploitationexploitationpost-exploitation+2
35 months ago
CVE-2026-24291 preview

CVE-2026-24291

GitHublennertdefauw/cve-2026-24291

Obfuscated Windows privilege escalation exploit for CVE-2026-24291 that automatically creates a local administrator with generated credentials.

exploitationpayload-developmentpost-exploitation+1
45 months ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubjishino567/cve-2026-73570

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

email-securityexploitationpenetration-testing+3
212 days ago
Previous12…37Next