Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
CVE-2025-21479-FX5P preview

CVE-2025-21479-FX5P

GitHubdiyiqiuye/cve-2025-21479-fx5p

Temporary root for OPPO Find X5 Pro (PFEM00) via CVE-2025-21479 + KernelSU LKM late-load (cloud-buildable)

android-securitybinary-exploitationexploitation+6
4 days ago
GoCD_PoC_Supply_Chain_Attack preview

GoCD_PoC_Supply_Chain_Attack

GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

educationexploitationpayload-generation+7
212 days ago
MSRMapper preview

MSRMapper

GitHubull0a/msrmapper

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

binary-exploitationexploitationmemory-forensics+6
112 days ago
ReflectiveDLLInjection preview

ReflectiveDLLInjection

GitHubstephenfewer/reflectivedllinjection

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

exploitationmemory-forensicspayload-development+2
3.4k4 years ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
13 months ago
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

command-and-controlexploitationmemory-forensics+6
11 month ago
SharpWhispers preview

SharpWhispers

GitHubsecforce/sharpwhispers

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

ids-ips-evasionpayload-developmentpost-exploitation+2
1123 years ago
AzTokenFinder preview

AzTokenFinder

GitHubhackmichnet/aztokenfinder

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

authenticationcloud-securitymemory-forensics+3
1093 years ago
clroxide preview

clroxide

GitHubyamakadi/clroxide

A rust library that allows you to host the CLR and execute dotnet binaries.

payload-developmentpost-exploitationred-teaming
2351 year ago
Chaos-Rootkit preview

Chaos-Rootkit

GitHubzeromemoryex/chaos-rootkit

Now You See Me, Now You Don't

ids-ips-evasionpersistence-mechanismspost-exploitation+2
1.1k4 months ago
LsassReflectDumping preview

LsassReflectDumping

GitHuboffensive-panda/lsassreflectdumping

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

memory-forensicspassword-attackspost-exploitation+1
2181 year ago
moonwalk preview

moonwalk

GitHubteach2breach/moonwalk

find dll base addresses without PEB WALK

binary-analysiseducationpayload-development+2
1691 year ago
PS4-5.05-Kernel-Exploit preview

PS4-5.05-Kernel-Exploit

GitHubkpwn/ps4-5.05-kernel-exploit

A fully implemented kernel exploit for the PS4 on 5.05FW

binary-exploitationembedded-systems-securityexploitation+3
268 years ago
loot-me preview

loot-me

GitHubrandomrobbiebf/loot-me

Collects files and commands post-exploitation, formats them into Markdown reports, and helps find sensitive information for red team reporting.

information-gatheringpenetration-testingpost-exploitation+2
6 years ago
diskwalker preview

diskwalker

GitHubnccgroup/diskwalker

Python script to efficiently find files on UNIX like file systems with specific properties (quicker than find)

information-gatheringpenetration-testingpost-exploitation+2
1911 years ago
CVE-2025-61304 preview

CVE-2025-61304

GitHubpentastic-be/cve-2025-61304

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

exploitationpayload-generationpost-exploitation+3
211 months ago
Elite preview

Elite

GitHubcobbr/elite

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

command-and-controldynamic-code-analysisencryption-decryption-tools+6
1217 years ago
inception preview

inception

GitHubcarmaa/inception

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

digital-forensicsexploitationhardware-security+6
1.6k1 year ago
Previous123Next