Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
p3-loader preview

p3-loader

GitHuborange-cyberdefense/p3-loader

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

binary-exploitationdefensive-toolseducation+8
212
1 month ago
CVE-2026-42758 preview

CVE-2026-42758

GitHubizxci/cve-2026-42758

Python exploit script for CVE-2026-42758 targeting WebinarIgnition. Supports custom target URLs, attacker email, verbose mode, and optional…

exploitationpenetration-testingred-teaming+2
2 months ago
cerebro-red-v2 preview

cerebro-red-v2

GitHubleviticus-triage/cerebro-red-v2

CEREBRO-RED v2: Advanced LLM Red Team Research Platform with PAIR Algorithm and LLM-as-a-Judge Evaluation

adversarial-attackai-securitydynamic-analysis-sandboxing+8
165 months ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubyoyochaud/cve-2025-49132

Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.

exploitationpayload-developmentpenetration-testing+3
256 months ago
php_filter_chains_oracle_exploit_for_CVE-2023-6199 preview

php_filter_chains_oracle_exploit_for_CVE-2023-6199

GitHubabdrrahimdahmani/php_filter_chains_oracle_exploit_for_cve-2023-6199

A CLI to exploit parameters vulnerable to PHP filter chain error based oracle, modified to exploit CVE-2023-6199

exploitationinformation-gatheringpenetration-testing+3
1 year ago
donut preview

donut

GitHubthewover/donut

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

exploitationids-ips-evasionmemory-forensics+7
4.7k1 year ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
Pluck-CMS-Stored-XSS---Installation preview

Pluck-CMS-Stored-XSS---Installation

GitHubsromanhu/pluck-cms-stored-xss---installation

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

payload-generationpenetration-testingred-teaming+3
2 years ago
CVE-2023-24488 preview

CVE-2023-24488

GitHubsecuritycipher/cve-2023-24488

POC for CVE-2023-24488

exploitationpenetration-testingred-teaming+2
143 years ago
ntqueueapcthreadex-ntdll-gadget-injection preview

ntqueueapcthreadex-ntdll-gadget-injection

GitHublloydlabs/ntqueueapcthreadex-ntdll-gadget-injection

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

adversarial-attackids-ips-evasionpayload-development+3
2673 years ago
SharpEventPersist preview

SharpEventPersist

GitHubimprosec/sharpeventpersist

Persistence by writing/reading shellcode from Event Log

payload-generationpersistence-mechanismspost-exploitation+1
3764 years ago
CVE-2021-26084_Confluence preview

CVE-2021-26084_Confluence

GitHubhev0x/cve-2021-26084_confluence

Python exploit for CVE-2021-26084, an OGNL injection vulnerability in Confluence Server/Data Center allowing authenticated or unauthenticated remote…

exploitationpayload-generationpenetration-testing+3
3174 years ago
social_mapper preview

social_mapper

GitHubgreenwolf/social_mapper

A Social Media Enumeration & Correlation Tool by Jacob Wilkin(Greenwolf)

information-gatheringosintpenetration-testing+4
4.1k4 years ago
PyFuscation preview

PyFuscation

GitHubcbhue/pyfuscation

Obfuscate powershell scripts by replacing Function names, Variables and Parameters.

payload-generationred-teamingscripting-automation
5256 years ago
CVE-2018-14665 preview

CVE-2018-14665

GitHubjas502n/cve-2018-14665

Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root…

exploitationpenetration-testingpost-exploitation+3
177 years ago
IoT-Implant-Toolkit preview

IoT-Implant-Toolkit

GitHubarthastang/iot-implant-toolkit

Toolkit for implant attack of IoT devices

binary-analysisembedded-systems-securityexploitation+8
1357 years ago