Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
170 results
CVE-2024-31317-PoC-Deployer preview

CVE-2024-31317-PoC-Deployer

GitHubwebldix/cve-2024-31317-poc-deployer

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

android-securitybinary-exploitationexploitation+5
53
1 year ago
SysWhispers3 preview

SysWhispers3

GitHubklezvirus/syswhispers3

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

defensive-toolsexploitationids-ips-evasion+5
1.7k2 years ago
Sandman preview

Sandman

GitHubidov31/sandman

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

command-and-controlpayload-generationpersistence-mechanisms+2
8182 years ago
PEzor-Docker preview

PEzor-Docker

GitHubcyb3r-techie/pezor-docker

With the help of this docker image, you can easily access PEzor on your system!

educationexploitationpayload-generation+2
154 years ago
phantom-frida preview

phantom-frida

GitHubtheqmaks/phantom-frida

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

android-securitybinary-analysisdynamic-analysis-sandboxing+7
3781 month ago
lacuna-rs preview

lacuna-rs

GitHubkarkas66/lacuna-rs

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

binary-exploitationpayload-developmentpost-exploitation+2
192 months ago
GoSH preview

GoSH

GitHubredcode-labs/gosh

Golang reverse/bind shell generator

exploitationpayload-developmentpayload-generation+4
2274 years ago
SdoKeyCrypt-sys-local-privilege-elevation preview

SdoKeyCrypt-sys-local-privilege-elevation

GitHubhypersine/sdokeycrypt-sys-local-privilege-elevation

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

binary-exploitationexploitationprivilege-escalation+2
847 years ago
CVE-2020-0022 preview

CVE-2020-0022

GitHubpolo35/cve-2020-0022

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)

android-securitybinary-exploitationbluetooth-security+5
375 years ago
avscript preview
Archived

avscript

GitHubtaviso/avscript

Avast JavaScript Interactive Shell

binary-analysisdebuggersexploitation+5
6736 years ago
xsser preview

xsser

GitHubvarbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

exploitationpayload-developmentpenetration-testing+3
4246 years ago
BadOutlook preview

BadOutlook

GitHubaahmad097/badoutlook

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

command-and-controlemail-securityexploitation+3
1375 years ago
Variatype.htb-CVE-2025-66034 preview

Variatype.htb-CVE-2025-66034

GitHubliquid1998/variatype.htb-cve-2025-66034

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

ctfexploitationpayload-generation+3
26 months ago
Rusty-Playground preview

Rusty-Playground

GitHubblacksnufkin/rusty-playground

Some Rust program I wrote while learning Malware Development

binary-analysisexploitationmalware-analysis+6
1601 year ago
cve_2022_0847_shellcode preview

cve_2022_0847_shellcode

GitHubshotokhan/cve_2022_0847_shellcode

Implementation of CVE-2022-0847 as a shellcode

binary-exploitationexploitationpayload-generation+3
34 years ago
LolModapi preview

LolModapi

GitHubmein-0/lolmodapi

Local privilege escalation exploit for MSI Dragon Center's MODAPI.sys driver, abusing unauthenticated MSR writes to bypass SMEP and gain SYSTEM.

binary-exploitationexploitationprivilege-escalation+2
16 days ago
CVE-2016-2067 preview

CVE-2016-2067

GitHubhhj4ck/cve-2016-2067

GPU IOMMU DMA exploit for Android devices that overwrites vdso.so with shellcode to escalate privileges and spawn a reverse root shell on Nexus 6p.

android-securitybinary-exploitationexploitation+5
75 years ago
CVE-2026-43499-RMX5200 preview

CVE-2026-43499-RMX5200

GitHubsorrow404null/cve-2026-43499-rmx5200

Android 16 local privilege escalation exploit for realme RMX5200 using LD_PRELOAD-based preload.so chain to achieve temporary root access via…

android-securitybinary-exploitationexploitation+6
62 months ago
Previous12…10Next