Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
Xiaomi-C200-Firmware-Analysis preview

Xiaomi-C200-Firmware-Analysis

GitHubh3xdum/xiaomi-c200-firmware-analysis

From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

data-recoveryembedded-systems-securityexploitation+6
11
9 months ago
LocalStranger preview

LocalStranger

GitHubnbs32k/localstranger

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

binary-exploitationexploit-frameworkspayload-development+3
43 days ago
php-bypass-disable-functions preview

php-bypass-disable-functions

GitHubirsl/php-bypass-disable-functions

Demo project how to bypass the disable_functions security control of PHP on Linux

binary-exploitationexploitationpost-exploitation+3
277 years ago
Titanis preview

Titanis

GitHubtrustedsec/titanis

Windows protocol library, including SMB and RPC implementations, among others.

authenticationcryptographyexploitation+7
8324 days ago
Dirty-Frag-Kubernetes-PoC preview

Dirty-Frag-Kubernetes-PoC

GitHubpercivalll/dirty-frag-kubernetes-poc

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

cloud-securitycontainer-escapeexploitation+3
184 months ago
Lime-RAT preview
Archived

Lime-RAT

GitHubnyan-x-cat/lime-rat

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

command-and-controlcryptographydata-exfiltration+7
1.1k7 years ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1287 years ago
BYOVD preview

BYOVD

GitHubblacksnufkin/byovd

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

educationexploitationids-ips-evasion+4
9511 month ago
CVE-2024-48208 preview

CVE-2024-48208

GitHubrohilchaudhry/cve-2024-48208

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

binary-exploitationexploitationpenetration-testing+3
71 year ago
awesome-oscp preview

awesome-oscp

GitHub0x4d31/awesome-oscp

A curated list of awesome OSCP resources

binary-exploitationcurated-resourceseducation+5
3.5k2 years ago
BoxPwnr preview

BoxPwnr

GitHub0ca/boxpwnr

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

ai-securityctfeducation+8
4592 months ago
CmdLineSpoofer preview

CmdLineSpoofer

GitHubplackyhacker/cmdlinespoofer

How to spoof the command line when spawning a new process from C#.

command-and-controleducationexploitation+5
1114 years ago
CVE-2024-48990-Exploit preview

CVE-2024-48990-Exploit

GitHubally-petitt/cve-2024-48990-exploit

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

exploitationpayload-developmentpenetration-testing+3
51 year ago
SparstanBoogie preview

SparstanBoogie

GitHubfuzzlove/sparstanboogie

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

educationexploitationios-security+4
33 months ago
CVE-2019-18634-writeup preview

CVE-2019-18634-writeup

GitHubdevteam6rabbit/cve-2019-18634-writeup

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

binary-exploitationctfeducation+4
8 months ago
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
7445 years ago
AV-EDR-Killer preview

AV-EDR-Killer

GitHubxm0kht4r/av-edr-killer

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

command-and-controlexploitationids-ips-evasion+5
2988 months ago
PrivFu preview

PrivFu

GitHubdaem0nc0re/privfu

Kernel mode WinDbg extension and PoCs for token privilege investigation.

exploitationpost-exploitationprivilege-escalation
1.0k14 days ago
Previous123Next