Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
387 results
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
1
1 day ago
CVE-2026-43499_HW-CLT-AL01 preview

CVE-2026-43499_HW-CLT-AL01

GitHubzychen027/cve-2026-43499_hw-clt-al01

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

android-securitybinary-exploitationexploitation+4
2 days ago
GhostLock-5.10 preview

GhostLock-5.10

GitHubr0rt1z2/ghostlock-5.10

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

android-securitybinary-exploitationexploitation+3
92 days ago
CVE-2026-68138 preview

CVE-2026-68138

GitHubjangkrikkbozz/cve-2026-68138

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

binary-exploitationexploitationpenetration-testing+1
3 days ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
11 month ago
Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284 preview

Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

GitHub6abc/copy-fail-cve-2026-31431-dirty-frag-cve-2026-43284
binary-exploitationexploitationprivilege-escalation+1
7 days ago
Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis preview

Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis

GitHubkaandemir993/agent-tesla-apc-injection-token-manipulation-registry-persistence-analysis

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

binary-analysisdata-exfiltrationeducation+4
313 days ago
PowerSploit preview

PowerSploit

GitHubzerodaylab/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

command-and-controldata-exfiltrationexploit-frameworks+7
2394 years ago
SharpCollection preview

SharpCollection

GitHubflangvik/sharpcollection

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

curated-resourcesexploitationlateral-movement+6
3.0k22 days ago
DylibHijackTest preview

DylibHijackTest

GitHubslyd0g/dylibhijacktest

Discover DYLD_INSERT_LIBRARIES hijacks on macOS

binary-analysisdynamic-analysis-sandboxingpersistence-mechanisms+2
453 years ago
JuicyPotatoNG preview

JuicyPotatoNG

GitHubantoniococo/juicypotatong

Another Windows Local Privilege Escalation from Service Account to System

exploitationpenetration-testingpost-exploitation+2
9673 years ago
SharpEfsPotato preview

SharpEfsPotato

GitHubbugch3ck/sharpefspotato

Local privilege escalation from SeImpersonatePrivilege using EfsRpc.

exploitationpenetration-testingpost-exploitation+2
3483 years ago
SharpStartWebclient preview

SharpStartWebclient

GitHubeversinc33/sharpstartwebclient

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

lateral-movementpenetration-testingpost-exploitation+2
803 years ago
RasmanPotato preview

RasmanPotato

GitHubcrisprss/rasmanpotato

Abuse Impersonate Privilege from Service to SYSTEM like other potatoes do

exploitationpenetration-testingpost-exploitation+2
4063 years ago
CVE-2026-64564 preview

CVE-2026-64564

GitHubhackspeak/cve-2026-64564

Local privilege escalation PoC for a Linux kernel SCTP ASCONF DEL-IP use-after-free, demonstrating a root shell from an unprivileged local user on…

binary-exploitationcontainer-escapeexploitation+3
513 days ago
LogMeInPoCHandleDup preview

LogMeInPoCHandleDup

GitHubalfarom256/logmeinpochandledup
binary-exploitationexploitationprivilege-escalation+2
642 years ago
CoercedPotatoRDLL preview

CoercedPotatoRDLL

GitHubsokarepo/coercedpotatordll

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

exploitationpayload-developmentpenetration-testing+4
2272 years ago
CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open preview

CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open

GitHubgeorge0papasotiriou/cve-2026-11111-toctou-in-file-permission-check-before-open
data-exfiltrationeducationexploitation+4
17 days ago
Previous12…22Next