Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
277 results
combine_harvester preview

combine_harvester

GitHubm3f157o/combine_harvester

Rust-based Windows LSASS credential dumper using MiniDumpWriteDump with custom callbacks to bypass EDR; includes GUI, CMD, and decryption modes for…

password-attackspenetration-testingpost-exploitation+1
109
3 years ago
PickleC2 preview

PickleC2

GitHubxret2pwn/picklec2

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

command-and-controllateral-movementpenetration-testing-frameworks+2
985 years ago
mssql-command-tool preview

mssql-command-tool

GitHubjas502n/mssql-command-tool

Command-line utility for connecting to Microsoft SQL Server and executing system commands using xp_cmdshell, with support for custom queries and…

database-securityexploitationlateral-movement+3
406 years ago
processhacker-mcp preview

processhacker-mcp

GitHubillegal-instruction-co/processhacker-mcp

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

debuggersdynamic-analysis-sandboxingexploitation+7
506 months ago
async-pico-hub preview

async-pico-hub

GitHubnccgroup/async-pico-hub

Event-driven asynchronous BOF execution framework for Cobalt Strike Beacon. Enables long-running custom event monitoring and real-time output from…

command-and-controlpayload-developmentpenetration-testing-frameworks+2
272 months ago
NewMachineAccount preview

NewMachineAccount

GitHubdecoder-it/newmachineaccount

Creates Active Directory machine accounts with custom passwords, supporting optional OU placement, explicit credentials, and UAC flag configuration.

exploitationpenetration-testingpost-exploitation+1
401 year ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
91 month ago
RemoteDLLInjector preview

RemoteDLLInjector

GitHubal1ex/remotedllinjector

Windows DLL injection tool that injects a custom DLL into a target process to deliver Meterpreter payloads and escalate privileges for remote access.

exploitationpayload-developmentpenetration-testing+3
95 years ago
best-CVE-2025-8088 preview

best-CVE-2025-8088

GitHubpentestfunctions/best-cve-2025-8088

Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation)

binary-exploitationexploitationpayload-development+4
100 years ago
Redis-RCE preview

Redis-RCE

GitHubal1ex/redis-rce

Exploit tool for Redis 4.x/5.x that achieves remote code execution by loading a custom RedisModule (exp.so) through a rogue server, enabling…

database-securityexploitationpenetration-testing+3
46 years ago
CVE-2021-34527 preview

CVE-2021-34527

GitHubausk1ll9/cve-2021-34527

PowerShell implementation of PrintNightmare LPE that adds a local administrator or runs a custom DLL payload.

exploitationpayload-developmentpenetration-testing+3
1 year ago
derpyc0w preview

derpyc0w

GitHubxpcmdshell/derpyc0w

C-based exploit for CVE-2016-5195 (Dirty COW) using a race condition to overwrite a read-only SUID executable with a custom ELF payload that elevates…

binary-exploitationexploitationpayload-development+3
8 years ago
CoffeeLdr preview
Archived

CoffeeLdr

GitHubcracked5pider/coffeeldr

Loads and executes Cobalt Strike Beacon Object Files outside the framework, enabling custom implants and standalone testing of BOF payloads.

command-and-controlpayload-developmentpenetration-testing+2
2942 years ago
blackpill preview
Archived

blackpill

GitHubshard77/blackpill

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

binary-exploitationcommand-and-controlids-ips-evasion+7
3385 months ago
SillyRAT preview

SillyRAT

GitHubhash3lizer/sillyrat

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

command-and-controlpayload-generationpost-exploitation+1
9383 years ago
MoveKit preview

MoveKit

GitHub0xthirteen/movekit

Cobalt Strike kit for Lateral Movement

exploit-frameworkslateral-movementpenetration-testing+2
6786 years ago
defcon33_silence_kill_edr preview

defcon33_silence_kill_edr

GitHubarosenmund/defcon33_silence_kill_edr

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

adversarial-attackeducationlabs-practice+6
3471 year ago
Crystal-Loaders preview

Crystal-Loaders

GitHubrasta-mouse/crystal-loaders

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

command-and-controlids-ips-evasionpayload-development+3
2414 months ago
Previous123…16Next