Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
CVE-2025-8110 preview

CVE-2025-8110

GitHubr3vpwnx/cve-2025-8110

Proof-of-concept exploit for CVE-2025-8110 in Gogs <=0.13.x, enabling authenticated symlink bypass to arbitrary file write as the Gogs process user,…

exploitationpenetration-testingprivilege-escalation+2
9 days ago
0xM0nCrush preview

0xM0nCrush

GitHubdeathshotxd/0xm0ncrush

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

defensive-toolsexploitationpayload-development+4
7714 days ago
Lumma-Stealer-dllhost-Hollowing-C2-Domains-Payload-Extraction-Analysis preview

Lumma-Stealer-dllhost-Hollowing-C2-Domains-Payload-Extraction-Analysis

GitHubkaandemir993/lumma-stealer-dllhost-hollowing-c2-domains-payload-extraction-analysis

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

binary-analysiscommand-and-controldata-exfiltration+4
1016 days ago
criPPLe preview

criPPLe

GitHubgmh5225/cripple

Windows kernel driver that removes Process Protection (PP) and Process Protection Light (PPL).

exploitationmalware-analysisprivilege-escalation+1
2 years ago
Mhyprot2DrvControl preview

Mhyprot2DrvControl

GitHubkagurazakasanae/mhyprot2drvcontrol

A lib that allows using mhyprot2 driver for enum process modules, r/w process memory and kill process.

privilege-escalationvulnerability-analysis
3625 years ago
evil-mhyprot-cli preview

evil-mhyprot-cli

GitHubkkent030315/evil-mhyprot-cli

A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.

binary-exploitationexploitationprivilege-escalation+2
3585 years ago
CVE-2026-4692-trust-me-im-in-rdm preview

CVE-2026-4692-trust-me-im-in-rdm

GitHubsneakynachos/cve-2026-4692-trust-me-im-in-rdm

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

exploitationexploit-frameworkspayload-development+4
123 days ago
CVE-2026-1880 preview

CVE-2026-1880

GitHubseokjohn/cve-2026-1880

ASUS DriverHub Driver Update Process TOCTOU Vulnerability Leading to LPE

binary-exploitationexploitationprivilege-escalation+1
55 months ago
ResourcePoison preview

ResourcePoison

GitHubmichalbednarski/resourcepoison

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

android-securityexploitationmobile-security+3
10711 months ago
CVE-2026-74939-escape-the-mac-n-cheese-box preview

CVE-2026-74939-escape-the-mac-n-cheese-box

GitHubsneakynachos/cve-2026-74939-escape-the-mac-n-cheese-box

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process…

binary-exploitationexploitationexploit-frameworks+3
124 days ago
CVE-2026-66804-CrossDevice-LPE preview

CVE-2026-66804-CrossDevice-LPE

GitHubdavidcarliez/cve-2026-66804-crossdevice-lpe

Local privilege escalation PoC for Windows CVE-2026-66804 using CrossDevice DLL planting and SigmaPotato token impersonation to spawn a SYSTEM…

binary-exploitationexploitationprivilege-escalation+1
121 month ago
PINKPANTHER preview

PINKPANTHER

GitHubwinterknife/pinkpanther

Windows x64 handcrafted token stealing kernel-mode shellcode

binary-exploitationpayload-developmentpost-exploitation+2
5192 years ago
breakcyserver preview

breakcyserver

GitHubwaawaa/breakcyserver

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

exploitationids-ips-evasionpost-exploitation+2
524 years ago
Checklists preview

Checklists

GitHubnetbiosx/checklists

Red Teaming & Pentesting checklists for various engagements

curated-resourceseducationlateral-movement+4
2.7k1 year ago
PPLFaultDumpBOF preview

PPLFaultDumpBOF

GitHubtrustedsec/pplfaultdumpbof

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

exploitationpost-exploitationprivilege-escalation+1
1463 years ago
LogMeInPoCHandleDup preview

LogMeInPoCHandleDup

GitHubalfarom256/logmeinpochandledup

Exploit for a LogMeIn/GoTo Windows kernel driver race condition that duplicates SYSTEM handles, enabling thread-token impersonation and local…

binary-exploitationexploitationprivilege-escalation+2
642 years ago
Enumprotections_BOF preview

Enumprotections_BOF

GitHuboctoberfest7/enumprotections_bof

A BOF to enumerate system process, their protection levels, and more.

information-gatheringpenetration-testingpost-exploitation+4
1261 year ago
CVE-2022-22706-poc preview

CVE-2022-22706-poc

GitHubbyt3quester/cve-2022-22706-poc

Proof-of-concept exploit for CVE-2022-22706: exploits a Mali GPU kernel driver page-cache write flaw to modify /etc/passwd in memory and obtain a…

android-securityexploitationprivilege-escalation+1
1 month ago
Previous1234Next