Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
387 results
cmdchamp preview

cmdchamp

GitHubmellen9999/cmdchamp

bash CLI trainer — 30 levels from ls to privilege escalation

ctfeducationforensics+8
1212h 20m ago
redamon preview

redamon

GitHubsamugit83/redamon

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

ai-securityexploit-frameworkslateral-movement+8
2.3k18h 9m ago
security-labs-pocs preview

security-labs-pocs

GitHubdatadog/security-labs-pocs

Proof of concept code for Datadog Security Labs referenced exploits.

container-escapecurated-resourcesexploitation+4
4501 day ago
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
1
CVE-2026-43499_HW-CLT-AL01 preview

CVE-2026-43499_HW-CLT-AL01

GitHubzychen027/cve-2026-43499_hw-clt-al01

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

android-securitybinary-exploitationexploitation+4
2 days ago
GhostLock-5.10 preview

GhostLock-5.10

GitHubr0rt1z2/ghostlock-5.10

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

android-securitybinary-exploitationexploitation+3
92 days ago
SAMDump preview

SAMDump

GitHubricardojoserf/samdump

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

data-exfiltrationencryption-decryption-toolspost-exploitation+3
3813 days ago
CVE-2026-68138 preview

CVE-2026-68138

GitHubjangkrikkbozz/cve-2026-68138

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

binary-exploitationexploitationpenetration-testing+1
3 days ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
4065 days ago
Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284 preview

Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

GitHub6abc/copy-fail-cve-2026-31431-dirty-frag-cve-2026-43284
binary-exploitationexploitationprivilege-escalation+1
7 days ago
CVE-2026-64564 preview

CVE-2026-64564

GitHubhackspeak/cve-2026-64564

Local privilege escalation PoC for a Linux kernel SCTP ASCONF DEL-IP use-after-free, demonstrating a root shell from an unprivileged local user on…

binary-exploitationcontainer-escapeexploitation+3
513 days ago
Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis preview

Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis

GitHubkaandemir993/agent-tesla-apc-injection-token-manipulation-registry-persistence-analysis

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

binary-analysisdata-exfiltrationeducation+4
313 days ago
wp2exp-2026 preview

wp2exp-2026

GitHubrechandra/wp2exp-2026

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030…

exploit-frameworkspayload-developmentpenetration-testing+5
516 days ago
CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open preview

CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open

GitHubgeorge0papasotiriou/cve-2026-11111-toctou-in-file-permission-check-before-open
data-exfiltrationeducationexploitation+4
17 days ago
CVE-2026-31431-copy-fail preview

CVE-2026-31431-copy-fail

GitHubtrevocastles/cve-2026-31431-copy-fail

Exploit PoC for CVE-2026-31431 that uses AF_ALG and splice() to overwrite Linux page cache and patch /usr/bin/su in memory, escalating unprivileged…

binary-exploitationexploitationpayload-development+1
18 days ago
CVE-2026-43499-Redmi-Turbo5 preview

CVE-2026-43499-Redmi-Turbo5

GitHubpetalrain224/cve-2026-43499-redmi-turbo5

Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege

android-securitybinary-exploitationeducation+4
419 days ago
CVE-2026-54121-CertiGhost preview

CVE-2026-54121-CertiGhost

GitHubkrakeneu/cve-2026-54121-certighost

CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

authentication-authorizationexploitationpenetration-testing+3
120 days ago
Metasploit-CVE-2026-54121-Certighost preview

Metasploit-CVE-2026-54121-Certighost

GitHubnafiez/metasploit-cve-2026-54121-certighost

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase"…

exploitationexploit-frameworkspenetration-testing+3
420 days ago
Previous12…22Next
1 day ago