Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
306 results
D-RAT_VB.NET_MySQL_PHP preview

D-RAT_VB.NET_MySQL_PHP

GitHubmr-wolf-gb/d-rat_vb.net_mysql_php

D-RAT [VB.NET]+[MySQL]+[PHP]

command-and-controlpayload-developmentpenetration-testing+3
14
6 years ago
CVE-2026-65643-PoC-Toolkit preview

CVE-2026-65643-PoC-Toolkit

GitHubtc4dy/cve-2026-65643-poc-toolkit

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

command-and-controlexploitationpayload-development+7
1225 days ago
CVE-2026-57239 preview

CVE-2026-57239

GitHubparadoxis/cve-2026-57239

Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader…

binary-exploitationexploitationpayload-development+4
162 months ago
lacuna-rs preview

lacuna-rs

GitHubkarkas66/lacuna-rs

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

binary-exploitationpayload-developmentpost-exploitation+2
193 months ago
Apollo preview

Apollo

GitHubobsida-uk/apollo

A simple, lightweight Remote Access Tool written in Python

command-and-controlpayload-generationpenetration-testing+3
167 years ago
refreshing-soap-exploit preview

refreshing-soap-exploit

GitHubrbowes-r7/refreshing-soap-exploit

A PoC exploit for CVE-2022-41622 - a CSRF in F5 BIG-IP control plane that leads to remote root

command-and-controlexploitationpayload-development+7
223 years ago
CVE-2020-0668 preview

CVE-2020-0668

GitHubycdxsb/cve-2020-0668

Make CVE-2020-0668 exploit work for version < win10 v1903 and version >= win10 v1903

binary-exploitationexploitationpayload-generation+2
144 years ago
Sub7 preview

Sub7

GitLabillwill/sub7

Source code for SubSeven 2.1.3

command-and-controlmalware-analysispayload-generation+2
152 years ago
CVE-2025-29824-Exploit preview

CVE-2025-29824-Exploit

GitHubafanpan/cve-2025-29824-exploit

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

binary-exploitationexploitationmalware-analysis+6
201 year ago
CVE-2016-0040 preview

CVE-2016-0040

GitHubde7ec7ed/cve-2016-0040

64-bit Windows kernel privilege escalation exploit for CVE-2016-0040 (WMI Receive Notification vulnerability) using GDI bitmap manipulation for token…

binary-exploitationexploitationpayload-development+3
149 years ago
CcmMessagingBackdoor preview

CcmMessagingBackdoor

GitHubsynacktiv/ccmmessagingbackdoor

Proof-of-concept backdoor for SCCM Management Point using rogue COM service for persistent remote command execution as SYSTEM.

command-and-controlpayload-developmentpersistence-mechanisms+3
191 year ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub0x00jeff/cve-2025-27591

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

binary-exploitationexploitationpayload-development+5
153 months ago
CVE-2025-32432-exploit-by-P34NUT preview

CVE-2025-32432-exploit-by-P34NUT

GitHubp34nut2/cve-2025-32432-exploit-by-p34nut

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

exploitationpayload-developmentpenetration-testing+6
713 days ago
CVE-2026-78006-POC preview

CVE-2026-78006-POC

GitHubdeadexpl0it/cve-2026-78006-poc

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

defensive-toolsexploitationpayload-development+7
418 days ago
CVE-2026-49176_BOF preview

CVE-2026-49176_BOF

GitHub777erp/cve-2026-49176_bof

CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)

exploitationpayload-developmentpost-exploitation+2
52 months ago
SSCMS-PluginShell preview

SSCMS-PluginShell

GitHubrichard-tang/sscms-pluginshell

CVE-2022-28118

command-and-controlexploitationpayload-development+3
84 years ago
njutils preview

njutils

GitHubseep1959/njutils

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

command-and-controlpayload-developmentpenetration-testing+3
78 years ago
RemoteDLLInjector preview

RemoteDLLInjector

GitHubal1ex/remotedllinjector

RemoteDLLInjector

exploitationpayload-developmentpenetration-testing+3
95 years ago
Previous1…111213…17Next