Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1035 results
bpfjailer preview

bpfjailer

GitHubfacebookincubator/bpfjailer

eBPF LSM based Mandatory Access Control and jailer

authentication-authorizationconfiguration-auditingcontainer-security+3
36
1 day ago
veneficus-implant-public preview

veneficus-implant-public

GitHubabraxas/veneficus-implant-public

Spicy malware 0day. Full kill-chain malware: exploit, pivot, c2, persistence. Rust converted to pseudo-code - if you're smart you can build it…

command-and-controldata-exfiltrationexploitation+9
1 month ago
veneficus preview

veneficus

GitHubabraxas/veneficus

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

command-and-controldata-exfiltrationids-ips-evasion+8
21 month ago
byd-dolphin-hacking preview

byd-dolphin-hacking

GitHubwheregoes/byd-dolphin-hacking

Reverse engineering the BYD Dolphin head unit — CAN bus, AVAS, NFC keys, OTA, and more. DiLink 3 / Android 10.

android-securitybinary-analysisembedded-systems-security+7
595 days ago
CVE-2026-14281 preview

CVE-2026-14281

GitHublangz337/cve-2026-14281

Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin…

exploitationpassword-attackspenetration-testing+6
111 days ago
Xenon preview

Xenon

GitHubmythicagents/xenon

A Mythic agent for Windows written in C

command-and-controldata-exfiltrationdefensive-tools+9
1831 month ago
CVE-2026-18782-TREX-MES-Uygulamalarinda-SQL-Zafiyeti preview

CVE-2026-18782-TREX-MES-Uygulamalarinda-SQL-Zafiyeti

GitHubhasanuyarrr/cve-2026-18782-trex-mes-uygulamalarinda-sql-zafiyeti

Advisory and technical write-up for CVE-2026-18782, a critical SQL injection in TREX MES web API endpoints enabling auth bypass, data theft, and RCE…

authenticationexploitationlateral-movement+5
7 days ago
SOC335---CVE-2024-49138-Exploitation-Detected preview

SOC335---CVE-2024-49138-Exploitation-Detected

GitHubfabianch20/soc335---cve-2024-49138-exploitation-detected

SOC335 incident response walkthrough for CVE-2024-49138 CLFS privilege escalation, covering alert triage, threat intel enrichment, process tree…

digital-forensicseducationincident-response+7
21 days ago
honor-6.12.38-43499-research preview

honor-6.12.38-43499-research

GitHubpyyyc/honor-6.12.38-43499-research

Research repository documenting exploitation attempts of CVE-2026-43499 futex UAF on Honor YLP-W00 kernel 6.12.38, including PoC sources, kernel…

android-securitybinary-exploitationexploitation+5
13 days ago
CVE-2026-24516-DigitalOcean-RCE. preview

CVE-2026-24516-DigitalOcean-RCE.

GitHubpoxsky/cve-2026-24516-digitalocean-rce.

Technical analysis and PoC for CVE-2026-24516: Unauthenticated Root Remote Code Execution in DigitalOcean Droplet Agent (CVSS 10.0).

cloud-securityexploitationinformation-gathering+7
6 months ago
CVE-2026-23111-PoC preview

CVE-2026-23111-PoC

GitHubimeiplus/cve-2026-23111-poc

Working local privilege escalation exploit for CVE-2026-23111, a use-after-free in the Linux kernel nf_tables subsystem, with KASLR bypass and ROP…

binary-exploitationeducationexploitation+3
17 days ago
kube-reaper preview

kube-reaper

GitHubstillbigjosh/kube-reaper

Scans Kubernetes clusters from any identity, flags dangerous permissions, and chains them into multi-step escalation paths to cluster compromise.

cloud-securityconfiguration-auditingcontainer-security+9
321 days ago
gvcidrv64 preview

gvcidrv64

GitHubmein-0/gvcidrv64

Proof-of-concept exploit for Gigabyte's GVCIDrv64.sys kernel driver, achieving local privilege escalation via arbitrary physical memory and I/O port…

binary-exploitationexploitationhardware-security+4
112 days ago
CVE-2026-67279 preview

CVE-2026-67279

GitHubhackspeak/cve-2026-67279

Python proof-of-concept scripts for the MikroTrick MikroTik RouterOS SSH takeover chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) for…

authenticationembedded-systems-securityexploitation+7
411 days ago
CVE-2026-65660-Poc preview

CVE-2026-65660-Poc

GitHubshadowforge-cyber/cve-2026-65660-poc

Malicious Register Directive Code Injection Exploit

command-and-controldata-exfiltrationexploitation+8
112 days ago
Kestra-cve-2026-53576 preview

Kestra-cve-2026-53576

GitHubatlasvector/kestra-cve-2026-53576

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

container-securityexploitationincident-response+8
12 days ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubhitechcloud-vietnam/cve-2026-41940-poc

Exploits CVE-2026-41940, a cPanel & WHM authentication bypass, to gain root WHM access and run post-exploitation commands, file reads, and account…

authenticationcommand-and-controlexploitation+8
11 days ago
libprocesshider preview

libprocesshider

GitHubgianlucaborello/libprocesshider

LD_PRELOAD shared library that hides a Linux process from tools like ps and lsof by intercepting readdir and proc filesystem calls.

defensive-toolsinformation-gatheringmalware-analysis+4
1.1k7 years ago
Previous12…58Next