Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
4 days ago
metasploitable-pentest-lab preview

metasploitable-pentest-lab

GitHubmboatella25/metasploitable-pentest-lab

Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales,…

educationexploitationinformation-gathering+9
2 months ago
CVE-2026-6018-9-Local-Privilege-Escalation-Chain preview

CVE-2026-6018-9-Local-Privilege-Escalation-Chain

GitHubm0r4a/cve-2026-6018-9-local-privilege-escalation-chain

Exploit chain for local privilege escalation on SUSE Linux, chaining PAM environment injection and a udisks2 race condition to obtain a root shell.

exploitationpenetration-testingpost-exploitation+3
14 months ago
HTB-Pterodactyl-Writeup preview

HTB-Pterodactyl-Writeup

GitHubv0idw1re/htb-pterodactyl-writeup

HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM…

ctfeducationexploitation+9
5 months ago
SSH-Snake preview
Archived

SSH-Snake

GitHubmegamansec/ssh-snake

SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.

information-gatheringlateral-movementnetwork-mapping+5
2.3k5 months ago
chisel-ng preview

chisel-ng

GitHubnullsection/chisel-ng

Chisel new generation, written in rust. SSH under WSS with some customization.

command-and-controlids-ips-evasionlateral-movement+5
1357 months ago
ZeroPulse preview

ZeroPulse

GitHubjxroot/zeropulse

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

command-and-controlexploitationlateral-movement+8
1448 months ago
Hawk preview

Hawk

GitHubprodefense/hawk

Golang tool designed to exfiltrate passwords found via the sshd and su services

data-exfiltrationinformation-gatheringpassword-attacks+3
389 months ago
DynastyPersist preview

DynastyPersist

GitHubtrevohack/dynastypersist

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

ctfpenetration-testingpersistence-mechanisms+3
1611 year ago
SSH-Stealer preview

SSH-Stealer

GitHubdarkspacesecurity/ssh-stealer

Smart keylogging capability to steal SSH Credentials including password & Private Key

data-exfiltrationpassword-attackspenetration-testing+2
1531 year ago
sshimpanzee preview

sshimpanzee

GitHublexfo/sshimpanzee

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

command-and-controldns-analysisnetwork-security+4
2941 year ago
Exploit-CVE-2014-4210- preview

Exploit-CVE-2014-4210-

GitHubzorvithonleo/exploit-cve-2014-4210-

Exploit for CVE-2014-4210 targeting WebLogic deserialization, with post-exploitation features including ransomware deployment, C2 integration, and…

command-and-controldata-exfiltrationexploitation+7
21 year ago
CVE-2024-415770-ssrf-rce preview

CVE-2024-415770-ssrf-rce

GitHub0dinox/cve-2024-415770-ssrf-rce

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

exploitationpayload-developmentpenetration-testing+3
21 year ago
boopkit preview

boopkit

GitHubkrisnova/boopkit

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

command-and-controlexploitationids-ips-evasion+6
1.7k3 years ago
PE_CVE-CVE-2021-3156 preview

PE_CVE-CVE-2021-3156

GitHubpurpleozone/pe_cve-cve-2021-3156

Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts

binary-exploitationeducationexploitation+6
73 years ago
freedomfighting preview

freedomfighting

GitHubjusticerage/freedomfighting

A collection of scripts which may come in handy during your freedom fighting activities.

crawlerencryption-decryption-toolsforensics+8
4183 years ago
reverse-ssh preview

reverse-ssh

GitHubfahrj/reverse-ssh

Statically-linked ssh server with reverse shell functionality for CTFs and such

ctfpenetration-testingpost-exploitation+2
1.1k3 years ago
SSHession preview

SSHession

GitHubnccgroup/sshession

The SSH Multiplex Backdoor Tool

authentication-authorizationexploitationlateral-movement+3
656 years ago
Previous12Next