Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
NfSpy preview

NfSpy

GitHubbonsaiviking/nfspy

ID-spoofing NFS client

authenticationexploitationinformation-gathering+4
3006 years ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1287 years ago
cobaltstrike-headless preview

cobaltstrike-headless

GitHubcodextf2/cobaltstrike-headless

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

command-and-controllateral-movementpenetration-testing+4
1474 years ago
pytmipe preview

pytmipe

GitHubquentinhardy/pytmipe

Python library and client for token manipulations and impersonations for privilege escalation on Windows

impersonation-toolspenetration-testingpost-exploitation+2
1233 years ago
CVE-2023-20178 preview

CVE-2023-20178

GitHubwh04m1001/cve-2023-20178

Proof-of-concept for arbitrary file delete vulnerability in Cisco Secure Client and AnyConnect, enabling privilege escalation to SYSTEM via Windows…

exploitationpenetration-testingprivilege-escalation+2
893 years ago
sccmsqlclient preview

sccmsqlclient

GitHubsynacktiv/sccmsqlclient

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

database-securityexploitationinformation-gathering+6
323 months ago
CVE-2024-2432-PaloAlto-GlobalProtect-EoP preview

CVE-2024-2432-PaloAlto-GlobalProtect-EoP

GitHubhagrid29/cve-2024-2432-paloalto-globalprotect-eop

Proof-of-concept exploit for CVE-2024-2432 demonstrating local privilege escalation on Windows via arbitrary file delete through symbolic link attack…

binary-exploitationexploitationpenetration-testing+2
632 years ago
Anvil preview

Anvil

GitHubshellkraft/anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

binary-analysisexploitationpenetration-testing+5
386 months ago
CVE-2024-0311 preview

CVE-2024-0311

GitHubcalligraf0/cve-2024-0311

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

binary-exploitationexploitationids-ips-evasion+4
91 year ago
CVE-2021-30357_CheckPoint_SNX_VPN_PoC preview

CVE-2021-30357_CheckPoint_SNX_VPN_PoC

GitHubjoaovarelas/cve-2021-30357_checkpoint_snx_vpn_poc

Proof-of-Concept for privileged file read through CheckPoint SNX VPN Linux Client

exploitationpenetration-testingprivilege-escalation+2
63 years ago
windows-smb-vulnerability-framework-cve-2025-33073 preview

windows-smb-vulnerability-framework-cve-2025-33073

GitHubsfrdevelopment/windows-smb-vulnerability-framework-cve-2025-33073

Research framework for CVE-2025-33073, a Windows SMB Client privilege escalation vulnerability. Provides malicious SMB server and client exploit…

exploitationexploit-frameworkspenetration-testing+2
611 months ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
CVE-2020-5752-Druva-inSync-Windows-Client-6.6.3---Local-Privilege-Escalation-PowerShell- preview

CVE-2020-5752-Druva-inSync-Windows-Client-6.6.3---Local-Privilege-Escalation-PowerShell-

GitHubyevh/cve-2020-5752-druva-insync-windows-client-6.6.3---local-privilege-escalation-powershell-

Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell) RCE

exploitationpayload-generationpenetration-testing+2
43 years ago
CVE-2023-38041-POC preview

CVE-2023-38041-POC

GitHubewilded/cve-2023-38041-poc

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

binary-exploitationexploitationpenetration-testing+2
22 years ago
Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation preview

Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation

GitHubhophouse/ivanti-pulse_vpn-client_exploit-cve-2023-35080_privilege-escalation

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

binary-exploitationexploitationexploit-frameworks+2
12 years ago
CVE-2023-7016-POC preview

CVE-2023-7016-POC

GitHubewilded/cve-2023-7016-poc

POC for the flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows that allows an attacker to execute code at a SYSTEM level via…

exploitationpenetration-testingprivilege-escalation+1
12 years ago
CVE-2021-25253 preview

CVE-2021-25253

GitHubmsd0pe-1/cve-2021-25253

Local privilege escalation exploit for Trend Micro OfficeScan Client <=10.0 via misconfigured ACLs on the installation folder, enabling system-level…

exploitationmisconfigurationpayload-generation+2
13 years ago
CVE-2024-11467 preview

CVE-2024-11467

GitHubnull-event/cve-2024-11467

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

binary-exploitationcode-analysisexploitation+4
7 months ago
Previous123Next