Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2022-37706 preview

CVE-2022-37706

GitHubd3ndr1t30x/cve-2022-37706

Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp…

exploitationpenetration-testingpost-exploitation+3
1
1 year ago
CVE-2023-22809-sudoedit-privesc preview

CVE-2023-22809-sudoedit-privesc

GitHubn3m1sys/cve-2023-22809-sudoedit-privesc

A script to automate privilege escalation with CVE-2023-22809 vulnerability

exploitationpenetration-testingpost-exploitation+3
1653 years ago
USP preview

USP

GitHubgrahamhelton/usp

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

payload-developmentpersistence-mechanismspost-exploitation+2
1532 years ago
CVE-2025-50154-Aggressor-Script preview

CVE-2025-50154-Aggressor-Script

GitHubash1996x/cve-2025-50154-aggressor-script

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

command-and-controlctfeducation+9
111 months ago
Hijack-service-binaries preview

Hijack-service-binaries

GitHubsec-zone/hijack-service-binaries

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

penetration-testingpost-exploitationprivilege-escalation+2
5 months ago
sshkey-grab preview

sshkey-grab

GitHubnetspi/sshkey-grab

Grab ssh keys from ssh-agent

exploitationmemory-forensicspost-exploitation
22311 years ago
NorkNork preview

NorkNork

GitHubn00py/norknork

Powershell Empire Persistence finder

defensive-toolsforensicsincident-response+2
1189 years ago
linux-privilege-escalation preview

linux-privilege-escalation

GitHubrexpository/linux-privilege-escalation

Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability

binary-exploitationexploitationpenetration-testing+3
94 years ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
16 days ago
CVE-2026-39987_PoC preview

CVE-2026-39987_PoC

GitHubwind010/cve-2026-39987_poc

A proof-of-concept for CVE-2026-39987

exploitationpenetration-testingpost-exploitation+2
125 days ago
CVE-2025-4517-POC-Sudoers preview

CVE-2025-4517-POC-Sudoers

GitHubbgutowski/cve-2025-4517-poc-sudoers

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

exploitationpayload-developmentpenetration-testing+3
6 months ago
CVE-2024-415770-ssrf-rce preview

CVE-2024-415770-ssrf-rce

GitHub0dinox/cve-2024-415770-ssrf-rce

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

exploitationpayload-developmentpenetration-testing+3
11 year ago
CVE-2022-1257 preview

CVE-2022-1257

GitHubkayes817/cve-2022-1257

Proof-of-concept exploit for CVE-2022-1257 that extracts and decrypts stored credentials from the McAfee Agent database (ma.db) using PowerShell.

educationexploitationpassword-cracking+2
1 year ago
arducky preview

arducky

GitLabcreased/arducky

Arducky - Arduino Ducky Script Interpreter

hardware-hackingpayload-generationpenetration-testing+2
18 years ago
Cohab_Processes preview

Cohab_Processes

GitHuboctoberfest7/cohab_processes

A small Aggressor script to help Red Teams identify foreign processes on a host machine

information-gatheringpenetration-testingpost-exploitation+2
893 years ago
sticky_keys_hunter preview

sticky_keys_hunter

GitHubztgrace/sticky_keys_hunter

A script to test an RDP host for sticky keys and utilman backdoor.

penetration-testingpost-exploitationremote-access-tool+1
2639 years ago
Sinister preview

Sinister

GitHubpushpenderindia/sinister

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

data-exfiltrationinformation-gatheringpassword-cracking+5
4661 year ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubkill1234545/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authentication-authorizationexploitationpenetration-testing+5
103 months ago
Previous12Next