Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
132 results
redamon preview

redamon

GitHubsamugit83/redamon

Autonomous AI red team framework that chains reconnaissance, exploitation, and post-exploitation into a single pipeline, then triages findings,…

ai-securityexploit-frameworkslateral-movement+8
3.0k
12h 14m ago
wesng preview

wesng

GitHubbitsadmin/wesng

Windows Exploit Suggester - Next Generation

exploitationinformation-gatheringprivilege-escalation+1
5.0k4 days ago
SharpHound preview

SharpHound

GitHubspecterops/sharphound

Collects Active Directory object metadata, group memberships, sessions, ACLs, and trusts to feed BloodHound attack-path mapping for security…

information-gatheringlateral-movementpenetration-testing+4
1.4k6 days ago
powerview.py preview

powerview.py

GitHubaniqfakhrul/powerview.py

Powerview on steroids

dns-analysisexploitationinformation-gathering+7
1.0k7 days ago
CVE-2026-13355 preview

CVE-2026-13355

GitHubmurrez/cve-2026-13355

Python PoC scanner and exploit for CVE-2026-13355, an unauthenticated admin privilege escalation in Meta Box AIO WordPress plugins, with FOFA mass…

exploitationinformation-gatheringpenetration-testing+6
15 days ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
116 days ago
couchdb-exploit preview

couchdb-exploit

GitHubdarabium/couchdb-exploit

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

exploitationinformation-gatheringpenetration-testing+4
18 days ago
CVE-2026-12793 preview

CVE-2026-12793

GitHubmurrez/cve-2026-12793

Python PoC scanner and exploit for CVE-2026-12793, an unauthenticated privilege escalation in JetFormBuilder <=3.6.2 that creates WordPress admin…

exploitationinformation-gatheringpenetration-testing+7
521 days ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
41322 days ago
sunset-noontide-pentesting preview

sunset-noontide-pentesting

GitHubzales2004/sunset-noontide-pentesting

Description Professional penetration testing assessment of the Sunset: Noontide VulnHub machine, covering reconnaissance, service enumeration,…

ctfeducationexploitation+9
25 days ago
TaskHound preview

TaskHound

GitHub1r0bit/taskhound

Tool to enumerate privileged Scheduled Tasks on Remote Systems

information-gatheringlateral-movementpenetration-testing+4
3101 month ago
CVE-2024-28000-Exploit-Lab preview

CVE-2024-28000-Exploit-Lab

GitHubshawnng078-ops/cve-2024-28000-exploit-lab

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

educationexploitationlabs-practice+5
1 month ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
1 month ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubghostpels/cve-2026-18366

Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

exploitationinformation-gatheringprivilege-escalation+2
1 month ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubnxploited/cve-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

exploitationinformation-gatheringpost-exploitation+3
21 month ago
ghosthound preview

ghosthound

GitHubjvbotelho/ghosthound

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

exploitationinformation-gatheringlateral-movement+5
441 month ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
2441 month ago
CVE-2026-11961 preview

CVE-2026-11961

GitHubjohenlastgen-jlg/cve-2026-11961

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

exploitationinformation-gatheringmisconfiguration+5
12 months ago
Previous12…8Next