Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
One-Lin3r preview

One-Lin3r

GitHubd4vinci/one-lin3r

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

exploitationinformation-gatheringpayload-generation+4
1.8k10 months ago
SmmBackdoor preview

SmmBackdoor

GitHubcr4sh/smmbackdoor

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

exploitationfirmware-analysishardware-hacking+4
6352 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5444 years ago
FFM preview

FFM

GitHubjusticerage/ffm

Freedom Fighting Mode: open source hacking harness

command-and-controldata-exfiltrationinformation-gathering+6
3506 months ago
Lucifer preview

Lucifer

GitHubskiller9090/lucifer

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

data-exfiltrationinformation-gatheringpenetration-testing+4
3785 years ago
TotalRecall preview

TotalRecall

GitHubxaitax/totalrecall

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

data-exfiltrationexploitationinformation-gathering+5
1685 months ago
Enumprotections_BOF preview

Enumprotections_BOF

GitHuboctoberfest7/enumprotections_bof

A BOF to enumerate system process, their protection levels, and more.

information-gatheringpenetration-testingpost-exploitation+4
1251 year ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
WP-GDPR-Compliance-Plugin-Exploit preview

WP-GDPR-Compliance-Plugin-Exploit

GitHubaeroot/wp-gdpr-compliance-plugin-exploit

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…

exploitationpayload-generationpenetration-testing+3
47 years ago
berdav-CVE-2021-4034 preview

berdav-CVE-2021-4034

GitHubthejoyofhacking/berdav-cve-2021-4034

Exploit for CVE-2021-4034 (PwnKit) that provides a root shell via polkit pkexec. Includes a dry-run mode to test vulnerability and a one-liner script…

exploitationexploit-frameworkspenetration-testing+3
44 years ago
copyfail-alpine preview

copyfail-alpine

GitHub4n4s4zi/copyfail-alpine

More portable PoC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux

binary-exploitationexploitationpenetration-testing+3
14 months ago
pwnkit-helper preview

pwnkit-helper

GitHubdr4xp/pwnkit-helper

For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.

ctfexploitationpenetration-testing+2
11 year ago
Umbra preview

Umbra

GitHubh3xduck/umbra

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

command-and-controleducationencryption-decryption-tools+6
1375 years ago
CVE-2020-14321 preview

CVE-2020-14321

GitHubhoangkien1020/cve-2020-14321

Course enrolments allowed privilege escalation from teacher role into manager role to RCE

educationexploitationpayload-generation+4
445 years ago
CVE-2026-15409-15410-Framework preview

CVE-2026-15409-15410-Framework

GitHubtc4dy/cve-2026-15409-15410-framework

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

command-and-controleducationexploitation+7
56 days ago
CVE-2026-80467 preview

CVE-2026-80467

GitHubsangsenimanwartefak/cve-2026-80467

Python detection tool that fingerprints ACF Extended forms on WordPress and checks for publicly exposed role fields indicating CVE-2026-80467…

educationpenetration-testingprivilege-escalation+4
17 days ago
cve-2022-27666-exploits preview

cve-2022-27666-exploits

GitHubalbocoder/cve-2022-27666-exploits

There are 2 exploitation methods that exploit CVE-2022-27666. For more info on how to use these code bases please check my blog.

binary-exploitationeducationexploitation+2
23 years ago
Linux-Kernel-Exploit-LAB preview

Linux-Kernel-Exploit-LAB

GitHubsakilahamed/linux-kernel-exploit-lab

More specific : Dirty COW (CVE-2016-5195)

binary-exploitationeducationexploitation+3
2 years ago
Previous12345Next