Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
105 results
CVE-2021-4034 preview

CVE-2021-4034

GitHubn1et/cve-2021-4034

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

ctfexploitationpenetration-testing+2
4 years ago
Detection-and-Mitigation-for-CVE-2022-1679 preview

Detection-and-Mitigation-for-CVE-2022-1679

GitHubov3rwatch/detection-and-mitigation-for-cve-2022-1679

Shell script to detect and mitigate CVE-2022-1679, a use-after-free vulnerability in the Linux kernel's ath9k wireless driver that allows local…

exploitationprivilege-escalationvulnerability-analysis+1
3 years ago
CVE-2021-3560-Polkit-Privilege-Esclation preview

CVE-2021-3560-Polkit-Privilege-Esclation

GitHubsecnigma/cve-2021-3560-polkit-privilege-esclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

authenticationexploitationpenetration-testing+2
1263 years ago
CVE-2021-3560-PolkitPrivilegeEsclation preview

CVE-2021-3560-PolkitPrivilegeEsclation

GitHubyutasato88/cve-2021-3560-polkitprivilegeesclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

exploitationpenetration-testingpost-exploitation+3
5 months ago
MySQL-Fu.rb preview

MySQL-Fu.rb

GitHubhood3drob1n/mysql-fu.rb

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

database-securityexploitationpayload-generation+3
313 years ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Weaponized web shell

penetration-testingpost-exploitationprivilege-escalation+4
3.5k11 months ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
postshell preview

postshell

GitHubrek7/postshell

PostShell - Post Exploitation Bind/Backconnect Shell

anti-botcommand-and-controlpayload-generation+5
817 years ago
pwnkit-exploit preview

pwnkit-exploit

GitHubpetergottesman/pwnkit-exploit

Local privilege escalation exploit for CVE-2021-4034 in pkexec, providing a proof-of-concept that drops a root shell on vulnerable systems.

binary-exploitationexploitationpenetration-testing+2
384 years ago
CVE-2025-34322_CVE-2025-34323_Nagios_Log_Server preview

CVE-2025-34322_CVE-2025-34323_Nagios_Log_Server

GitHubmcorybillington/cve-2025-34322_cve-2025-34323_nagios_log_server

Proof of Concept exploits for CVE-2025-34322 and CVE-2025-34323 in Nagios Log Server

command-and-controlexploitationpenetration-testing+3
9 months ago
hoaxshell preview

hoaxshell

GitHubt3l3machus/hoaxshell

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

command-and-controlexploitationpayload-generation+5
3.5k1 year ago
Umbra preview

Umbra

GitHubh3xduck/umbra

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

command-and-controleducationencryption-decryption-tools+6
1355 years ago
cve-2021-4034 preview

cve-2021-4034

GitHubzcrosman/cve-2021-4034

Shell implementation of CVE-2021-4034, a local privilege escalation exploit for pkexec, enabling privilege escalation on vulnerable Linux systems.

exploitationpenetration-testingprivilege-escalation+2
4 years ago
cve-2020-14008 preview

cve-2020-14008

GitHubjackhars/cve-2020-14008

Python exploit for CVE-2020-14008 in ManageEngine Applications Manager delivering a SYSTEM-level reverse shell via authenticated remote code…

exploitationpayload-generationpenetration-testing+4
51 year ago
Salsa-tools preview

Salsa-tools

GitHubhackplayers/salsa-tools

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

command-and-controlencryption-decryption-toolsexploitation+7
5896 years ago
CVE-2022-0847_dirty-pipe preview

CVE-2022-0847_dirty-pipe

GitHubludovicpatho/cve-2022-0847_dirty-pipe

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

binary-exploitationexploitationpayload-development+3
104 years ago
CVE-2021-3456 preview

CVE-2021-3456

GitHubmrk336/cve-2021-3456

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

command-and-controleducationexploitation+8
1 year ago
CVE-2023-42791_CVE-2024-23666 preview

CVE-2023-42791_CVE-2024-23666

GitHubsynacktiv/cve-2023-42791_cve-2024-23666

Exploitations scripts for CVE-2023-42791 and CVE-2024-23666.

command-and-controlexploitationpenetration-testing+5
61 year ago
Previous123456Next