Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
CVE-2026-15989 preview

CVE-2026-15989

GitHubfl0ydsec/cve-2026-15989

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts…

exploitationpayload-generationpenetration-testing+6
2 days ago
CVE-2026-92162 preview

CVE-2026-92162

GitHub0xsemizzz/cve-2026-92162

Educational write-up and test-mode PoC for CVE-2026-92162, a path traversal in Flatpak's DeployAppstream arch parameter enabling root directory…

educationexploitationpapers-research+4
118 days ago
cve-2026-6471-postgres-logical-decoding-dlopen preview

cve-2026-6471-postgres-logical-decoding-dlopen

GitHubgoldendivider/cve-2026-6471-postgres-logical-decoding-dlopen

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

database-securityexploitationpayload-development+4
1 month ago
hayduk preview

hayduk

GitHubjolovicdev/hayduk

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

exploit-frameworksnetwork-mappingpenetration-testing-frameworks+3
719 days ago
RunPE preview

RunPE

GitHubnettitude/runpe

C# Reflective loader for unmanaged binaries.

adversarial-attackimpersonation-toolspayload-development+6
4443 years ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
13 months ago
persistence-info.github.io preview

persistence-info.github.io

GitHubpersistence-info/persistence-info.github.io

Curated reference of Windows persistence mechanisms across registry, scheduled tasks, services, and more, designed to improve protection and…

curated-resourceseducationpersistence-mechanisms+1
5342 years ago
MoreImpacketExamples preview

MoreImpacketExamples

GitHubicyguider/moreimpacketexamples

More examples using the Impacket library designed for learning purposes.

data-exfiltrationeducationlateral-movement+3
2653 years ago
clroxide preview

clroxide

GitHubyamakadi/clroxide

A rust library that allows you to host the CLR and execute dotnet binaries.

payload-developmentpost-exploitationred-teaming
2351 year ago
Terminator preview

Terminator

GitHubzeromemoryex/terminator

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

adversarial-attackexploitationpost-exploitation+1
1.1k3 years ago
Enumprotections_BOF preview

Enumprotections_BOF

GitHuboctoberfest7/enumprotections_bof

A BOF to enumerate system process, their protection levels, and more.

information-gatheringpenetration-testingpost-exploitation+4
1251 year ago
Xenotix-Python-Keylogger preview

Xenotix-Python-Keylogger

GitHubajinabraham/xenotix-python-keylogger

Xenotix Python Keylogger for Windows.

data-exfiltrationpassword-attackspayload-development+3
4637 years ago
SmmBackdoor preview

SmmBackdoor

GitHubcr4sh/smmbackdoor

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

exploitationfirmware-analysishardware-hacking+4
6352 years ago
MAL-002 preview

MAL-002

GitHubmbadanoiu/mal-002

MAL-002: Force System Restart via Installed Windows MSIs

educationexploitationpost-exploitation+1
2 years ago
ExtensionHijack preview

ExtensionHijack

GitHubal1ex/extensionhijack

ExtensionHijack

persistence-mechanismspost-exploitationred-teaming
26 years ago
Fenrir preview

Fenrir

GitHubnccgroup/fenrir

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

command-and-controllateral-movementpenetration-testing+3
6711 years ago
Umbra preview

Umbra

GitHubh3xduck/umbra

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

command-and-controleducationencryption-decryption-tools+6
1375 years ago
RAT-via-Telegram preview

RAT-via-Telegram

GitHubritiek/rat-via-telegram

Removed according to regulations

command-and-controleducationpayload-development+3
359 years ago
Previous123Next