Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
1
7 days ago
CVE-2025-47812 preview

CVE-2025-47812

GitHub0xgh057r3c0n/cve-2025-47812

Wing FTP Server RCE via Lua Injection

exploitationpayload-developmentpenetration-testing+3
31 year ago
CVE-2025-47812 preview

CVE-2025-47812

GitHubblindma1den/cve-2025-47812

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…

educationexploitationpayload-generation+5
11 year ago
CVE-2025-47812-PoC preview

CVE-2025-47812-PoC

GitHubhavbay/cve-2025-47812-poc

Unauthenticated remote code execution exploit for Wing FTP Server (CVE-2025-47812) with multiple reverse shell payloads, interactive and CLI modes,…

educationexploitationpayload-generation+5
7 months ago
CVE-2025-471812-POC preview

CVE-2025-471812-POC

GitHubd3vn0mi/cve-2025-471812-poc

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

exploitationpayload-generationpenetration-testing+3
7 months ago
CVE-2020-9470 preview

CVE-2020-9470

GitHubal1ex/cve-2020-9470

Wing FTP Server 6.2.5 - Privilege Escalation

exploitationpenetration-testingprivilege-escalation+3
5 years ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
cve-2015-3636 preview

cve-2015-3636

GitHubludongxu/cve-2015-3636

Proof-of-concept exploit for CVE-2015-3636, a Linux kernel ping socket vulnerability enabling local privilege escalation.

binary-exploitationexploitationpenetration-testing+2
11 years ago
Cronos-Rootkit preview
Archived

Cronos-Rootkit

GitHubxaff-xaff/cronos-rootkit

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

ids-ips-evasionpersistence-mechanismspost-exploitation+2
9454 years ago
Chaos-Rootkit preview

Chaos-Rootkit

GitHubzeromemoryex/chaos-rootkit

Now You See Me, Now You Don't

ids-ips-evasionpersistence-mechanismspost-exploitation+2
1.1k4 months ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
2073 days ago
HookDump preview

HookDump

GitHubzeroperil/hookdump

Security product hook detection

binary-analysisdefensive-toolsred-teaming
3245 years ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
1113 days ago
captaincredz preview

captaincredz

GitHubsynacktiv/captaincredz

CaptainCredz is a modular and discreet password-spraying tool.

authenticationidentity-access-managementpassword-attacks+2
1401 month ago
MalleableC2Profiles preview

MalleableC2Profiles

GitHubbluscreenofjeff/malleablec2profiles

Malleable C2 profiles for Cobalt Strike

command-and-controlexploit-frameworksnetwork-security+3
779 years ago
DsArk64 preview

DsArk64

GitHubgmh5225/dsark64

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…

binary-exploitationdefensive-toolsexploitation+6
125 months ago
GoCD_PoC_Supply_Chain_Attack preview

GoCD_PoC_Supply_Chain_Attack

GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

educationexploitationpayload-generation+7
212 days ago
CVE-2026-1281-Ivanti-EPMM-RCE preview

CVE-2026-1281-Ivanti-EPMM-RCE

GitHubmehdiledeaut/cve-2026-1281-ivanti-epmm-rce

Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion

exploitationpayload-developmentpenetration-testing+3
67 months ago
Previous1234567Next