Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
595 results
CMD_Bypass_Assessment preview

CMD_Bypass_Assessment

GitHubalperenugurlu/cmd_bypass_assessment

PowerShell script that automatically tests CMD bypass methods on Windows, evaluates results, calculates a security score, and provides hardening…

configuration-auditingdefensive-toolseducation+1
11
3 years ago
MeterPwrShell preview
Archived

MeterPwrShell

GitHubgetrektboy724/meterpwrshell

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

command-and-controlexploit-frameworksids-ips-evasion+7
2274 years ago
unshackle preview
Archived

unshackle

GitHubfadi002/unshackle

Open-source tool to bypass windows and linux passwords from bootable usb

authentication-authorizationeducationpassword-attacks+3
2.0k2 years ago
EDRSandblast preview

EDRSandblast

GitHubwavestone-cdt/edrsandblast

Weaponizes vulnerable signed drivers to bypass EDR kernel callbacks, object callbacks, ETW TI provider, and userland hooks for LSASS memory dumping…

defensive-toolsexploitationpenetration-testing+2
1.8k2 years ago
EDRSandblast-GodFault preview
Archived

EDRSandblast-GodFault

GitHubgabriellandau/edrsandblast-godfault

EDRSandblast-GodFault

defensive-toolsexploitationmemory-forensics+4
2723 years ago
Evasor preview

Evasor

GitHubcyberark/evasor

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

binary-analysisdefensive-toolspenetration-testing+3
3266 years ago
PPLFaultDumpBOF preview

PPLFaultDumpBOF

GitHubtrustedsec/pplfaultdumpbof

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

exploitationpost-exploitationprivilege-escalation+1
1463 years ago
pixel-ksu-root preview

pixel-ksu-root

GitHubjingmatrix/pixel-ksu-root

adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched…

android-securityexploitationexploit-frameworks+6
78 days ago
ibombshell preview

ibombshell

GitHubtelefonica/ibombshell

Tool to deploy a post-exploitation prompt at any time

command-and-controlids-ips-evasionpayload-generation+5
3215 years ago
CVE-2021-3560 preview

CVE-2021-3560

GitHub0dayninja/cve-2021-3560

Polkit D-Bus Authentication Bypass Exploit

authentication-authorizationexploitationpayload-generation+3
95 years ago
DSCourier preview

DSCourier

GitHubdylandavis1/dscourier

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

configuration-auditingdefensive-toolspenetration-testing+3
2112 months ago
Salsa-tools preview

Salsa-tools

GitHubhackplayers/salsa-tools

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

command-and-controlencryption-decryption-toolsexploitation+7
5886 years ago
path-auditor preview
Archived

path-auditor

GitHubgoogle/path-auditor

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

binary-analysisdynamic-code-analysisexploitation+3
2505 years ago
VEN0m-Ransomware preview

VEN0m-Ransomware

GitHubxm0kht4r/ven0m-ransomware

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

encryption-decryption-toolsexploitationids-ips-evasion+6
3696 months ago
CVE-2025-4162030 preview

CVE-2025-4162030

GitHubnotitssixtyn3in/cve-2025-4162030

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162030) in Copilot, involving user ID switching that could lead to…

authenticationauthentication-authorizationincident-response+3
1 year ago
vmware_vcenter_cve_2020_3952 preview

vmware_vcenter_cve_2020_3952

GitHubguardicore/vmware_vcenter_cve_2020_3952

Exploit for CVE-2020-3952 in vCenter 6.7

authentication-authorizationexploitationpenetration-testing+3
2746 years ago
proftpd-CVE-2026-42167-poc preview

proftpd-CVE-2026-42167-poc

GitHubzeropathai/proftpd-cve-2026-42167-poc

POCs to demonstrate CVE-2026-42167 in ProFTPD

authentication-authorizationdatabase-securityeducation+6
244 months ago
CVE-2026-13610 preview

CVE-2026-13610

GitHubghostpels/cve-2026-13610

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

authentication-authorizationexploitationpenetration-testing+4
18 days ago
Previous12…34Next