Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
ARES preview

ARES

GitHubmafifrizi/ares

Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault,…

cloud-securitycommand-and-controldefensive-tools+5
478
2 days ago
NovaLdr preview

NovaLdr

GitHubblacksnufkin/novaldr

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

code-analysiseducationexploitation+7
2652 years ago
Silverseal preview

Silverseal

GitHubidov31/silverseal

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

binary-exploitationexploitationmalware-analysis+4
1615 months ago
scour preview

scour

GitHubgrines/scour

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

cloud-securityexploitationlateral-movement+4
1272 years ago
Azur3Alph4 preview

Azur3Alph4

GitHubhyd3sec/azur3alph4

PowerShell module for post-breach Azure red teaming, automating token extraction, resource enumeration, and lateral movement within managed identity…

cloud-securityinformation-gatheringpenetration-testing+3
635 years ago
WinRAR-CVE-2023-38831 preview

WinRAR-CVE-2023-38831

GitHubxaitax/winrar-cve-2023-38831

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is…

exploitationexploit-frameworkspayload-generation+3
173 years ago
VTIGER-CRM-RCE-CVE-2026-23698 preview

VTIGER-CRM-RCE-CVE-2026-23698

GitHubjivasecurity/vtiger-crm-rce-cve-2026-23698

Vtiger CRM 8.3.0, 8.4.0 Module Import Authenticated RCE PoC

exploitationpayload-developmentpenetration-testing+3
2 months ago
JXL_Infotainment_CVE-2025-69515 preview

JXL_Infotainment_CVE-2025-69515

GitHubthorat-shubham/jxl_infotainment_cve-2025-69515

Proof-of-concept exploit for CVE-2025-69515 demonstrating static GPS spoofing on JXL 9-inch Android infotainment units via SDR-based signal…

embedded-systems-securityexploitationhardware-iot-security+4
5 months ago
drupalgeddon2 preview

drupalgeddon2

GitHubjirojo2/drupalgeddon2

MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)

exploit-frameworkspayload-developmentpenetration-testing+3
58 years ago
sshprank preview

sshprank

GitHubnoptrix/sshprank

A fast SSH mass-scanner, login cracker, banner grabber and password auth checker tool using the python-masscan and shodan module.

information-gatheringnetwork-securitypassword-attacks+2
1794 months ago
nate158g-m-w-n-l-p-d-a-o-e preview

nate158g-m-w-n-l-p-d-a-o-e

GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

exploit-frameworkspayload-generationpenetration-testing-frameworks+3
154 years ago
CVE-2015-3224 preview

CVE-2015-3224

GitHub0x00-0x00/cve-2015-3224

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

exploit-frameworkspayload-developmentpenetration-testing+3
28 years ago
FreePBX-CVE-2025-57819 preview

FreePBX-CVE-2025-57819

GitHubyuvrajshad/freepbx-cve-2025-57819

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

command-and-controlexploitationpayload-development+5
13 months ago
Diamorphine preview

Diamorphine

GitHubm0nad/diamorphine

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

malware-analysispersistence-mechanismsprivilege-escalation+1
2.5k5 months ago
MaFrida preview

MaFrida

GitHubtheshinigami/mafrida

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

android-securitydynamic-analysis-sandboxingdynamic-code-analysis+5
412 months ago
PythonMemoryModule preview

PythonMemoryModule

GitHubnaksyn/pythonmemorymodule

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

exploit-frameworkspenetration-testingred-teaming
3382 years ago
CVE-2026-31431-Copy-Fail preview

CVE-2026-31431-Copy-Fail

GitHubrippsec/cve-2026-31431-copy-fail

Comprehensive analysis of CVE-2026-31431, a Linux kernel LPE, including exploit methodology, detection scripts, YARA rules, auditd and Falco…

educationexploitationincident-response+3
14 months ago
CrossC2 preview

CrossC2

GitHubgloxec/crossc2

generate CobaltStrike's cross-platform payload

command-and-controlexploit-frameworkspayload-development+4
2.6k3 years ago
Previous12345Next