Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2018-1058 preview

CVE-2018-1058

GitHubccchme/cve-2018-1058

Reproducible Docker-based demonstration of CVE-2018-1058 PostgreSQL privilege escalation via uncontrolled search path, with vulnerable and patched…

database-securityeducationexploitation+3
3 months ago
NetExec preview

NetExec

GitHubpennyw0rth/netexec

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

command-and-controldatabase-securityexploitation+14
5.8k1 day ago
CVE-2017-0213 preview

CVE-2017-0213

GitHubeonrickity/cve-2017-0213

Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.

binary-exploitationexploitationpenetration-testing+2
148 years ago
CVE-2023-38571-a-macOS-TCC-bypass-in-Music-and-TV preview

CVE-2023-38571-a-macOS-TCC-bypass-in-Music-and-TV

GitHubgergelykalman/cve-2023-38571-a-macos-tcc-bypass-in-music-and-tv

macOS TCC bypass exploit leveraging insecure file rename in Music and TV apps to gain Full Disk Access by overwriting the TCC database via a symlink…

exploitationpenetration-testingprivilege-escalation+2
132 years ago
CVE-2024-56429 preview

CVE-2024-56429

GitHublisa-2905/cve-2024-56429

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

database-securityexploitationpassword-attacks+2
1 year ago
AD_Miner preview

AD_Miner

GitHubad-security/ad_miner

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

configuration-auditingeducationinformation-gathering+6
1.6k5 months ago
win-exp- preview

win-exp-

GitHubianxtianxt/win-exp-

windwos辅助提权脚本

exploitationinformation-gatheringpenetration-testing+3
1096 years ago
proftpd-CVE-2026-42167-poc preview

proftpd-CVE-2026-42167-poc

GitHubzeropathai/proftpd-cve-2026-42167-poc

POCs to demonstrate CVE-2026-42167 in ProFTPD

authentication-authorizationdatabase-securityeducation+6
243 months ago
CVE-2026-2005 preview

CVE-2026-2005

GitHubvar77/cve-2026-2005

PoC for CVE-2026-2005

binary-exploitationdatabase-securityeducation+4
273 months ago
CVE-2023-39593 preview

CVE-2023-39593

GitHubant1sec-ops/cve-2023-39593

Database authenticated code execution

command-and-controldatabase-securityeducation+6
21 year ago
autobloody preview

autobloody

GitHubcravaterouge/autobloody

Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound

exploitationpenetration-testingprivilege-escalation
71210 months ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
CVE-2025-24999 preview

CVE-2025-24999

GitHubemad-almousa/cve-2025-24999

Proof-of-concept exploit for CVE-2025-24999, demonstrating privilege escalation in Microsoft SQL Server via the MS_DatabaseManager role.

database-securityexploitationpenetration-testing+2
4 months ago
msdat preview

msdat

GitHubquentinhardy/msdat

MSDAT: Microsoft SQL Database Attacking Tool

database-securityexploitationinformation-gathering+3
1.0k3 years ago
CVE-2026-22003-Redis-Lua-Sandbox-Escape-via-debug.sethook- preview

CVE-2026-22003-Redis-Lua-Sandbox-Escape-via-debug.sethook-

GitHubgeorge0papasotiriou/cve-2026-22003-redis-lua-sandbox-escape-via-debug.sethook-

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.

adversarial-attackdatabase-securityexploitation+2
22 days ago
cve-2016-6662 preview

cve-2016-6662

GitHubboompig/cve-2016-6662

Exploit code for MySQL remote root code execution and privilege escalation (CVE-2016-6662), including Python and C implementations.

database-securityexploitationpayload-development+3
19 years ago
Pentest-Tools-Framework preview
Archived

Pentest-Tools-Framework

GitHubpikpikcu/pentest-tools-framework

Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of…

educationexploitationexploit-frameworks+6
4631 year ago
One-Lin3r preview

One-Lin3r

GitHubd4vinci/one-lin3r

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

exploitationinformation-gatheringpayload-generation+4
1.8k8 months ago
Previous12Next