Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
57 results
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
25
3 days ago
CVE-2026-32710 preview

CVE-2026-32710

GitHubdinosn/cve-2026-32710

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

binary-exploitationdatabase-securityexploitation+4
154 months ago
voidmap preview

voidmap

GitHubsamueltulach/voidmap

Using CVE-2021-40449 to manual map kernel mode driver

binary-exploitationexploitationexploit-frameworks+2
1054 years ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
DiagTrackEoP preview

DiagTrackEoP

GitHubwh04m1001/diagtrackeop

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

adversarial-attackexploitationpenetration-testing+3
884 years ago
DirCreate2System preview

DirCreate2System

GitHubbinderlabs/dircreate2system

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

adversarial-attackeducationexploitation+4
3643 years ago
GIUDA preview

GIUDA

GitHubfoxlox/giuda

Ask a TGS on behalf of another user without password

authenticationexploitationimpersonation-tools+5
4801 year ago
CVE-2025-68937 preview

CVE-2025-68937

GitHubscratchappy/cve-2025-68937

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

exploitationpenetration-testingprivilege-escalation+3
1 month ago
CVE-2021-4034 preview

CVE-2021-4034

GitHubal1ex/cve-2021-4034

Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)

binary-exploitationeducationexploitation+2
44 years ago
refreshing-mcp-tool preview

refreshing-mcp-tool

GitHubrbowes-r7/refreshing-mcp-tool

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

database-securityexploitationinformation-gathering+5
73 years ago
QuickBox-Pro-2.1.8-Authenticated-RCE preview

QuickBox-Pro-2.1.8-Authenticated-RCE

GitHubs1gh/quickbox-pro-2.1.8-authenticated-rce

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

exploitationpenetration-testingpost-exploitation+3
6 years ago
CopyFail-CVE-2026-31431 preview

CopyFail-CVE-2026-31431

GitHubzephrfish/copyfail-cve-2026-31431

Linux kernel LPE exploit (CVE-2026-31431) using AF_ALG + splice to overwrite setuid-binary page cache for root. No race conditions, works on all…

binary-exploitationexploitationpenetration-testing+1
304 months ago
oxasploits preview

oxasploits

GitHuboxasploits/oxasploits

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

binary-exploitationbluetooth-securityexploitation+6
3 months ago
LSTAR-EN preview

LSTAR-EN

GitHubmoscowchill/lstar-en

LSTAR - CobaltStrike Translated to EN

command-and-controlexploitationids-ips-evasion+9
233 years ago
dirtyPipe-automaticRoot preview

dirtyPipe-automaticRoot

GitHubnanaao/dirtypipe-automaticroot

CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.

binary-exploitationexploitationpayload-generation+2
44 years ago
CVE-2020-3153 preview

CVE-2020-3153

GitHubshubham0d/cve-2020-3153

POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability

exploitationpenetration-testingpost-exploitation+3
56 years ago
Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability preview

Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability

GitHubkasunpriyashan/y2s1-project-linux-exploitaion-using-cve-2016-5195-vulnerability

Educational Linux privilege escalation exploit targeting CVE-2016-5195 (Dirty COW) to demonstrate kernel vulnerability exploitation and root access…

binary-exploitationeducationexploitation+4
4 years ago
tools-for-CVE-2018-1000001 preview

tools-for-CVE-2018-1000001

GitHubusernameid0/tools-for-cve-2018-1000001

Tools for get offsets and adding patch for support i386

binary-exploitationexploitationpayload-development+3
4 years ago
Previous1234Next