Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
CVE-2022-23093 preview

CVE-2022-23093

GitHubsh4den/cve-2022-23093

The FreeBSD ICMP buffer overflow, freebsd buffer overflow poc

binary-exploitationexploitationpayload-development+2
10
1 month ago
Hollow preview

Hollow

GitHubchaelsoo/hollow

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

binary-exploitationencryption-decryption-toolsexploitation+7
1001 month ago
stealth_call preview

stealth_call

GitHubshare-devn/stealth_call

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

exploitationids-ips-evasionmemory-forensics+5
74 months ago
CVE-2018-2628 preview

CVE-2018-2628

GitHubherantong/cve-2018-2628

Python-based exploit for CVE-2018-2628 targeting Oracle WebLogic Server, providing vulnerability detection and remote shell access via JSP payload…

exploitationpayload-generationpenetration-testing+3
17 months ago
HackerLife.exe preview

HackerLife.exe

GitHubspiralbl0ck/hackerlife.exe

Write up exploit failed chain and experience tryin to sell your first nday

binary-exploitationeducationexploitation+5
1 year ago
nimvoke preview

nimvoke

GitHubnbaertsch/nimvoke

Indirect syscalls + DInvoke made simple.

ids-ips-evasionpayload-developmentpost-exploitation+2
951 year ago
CVE-2024-10793 preview

CVE-2024-10793

GitHubmahajian/cve-2024-10793

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

exploitationpayload-developmentprivilege-escalation+3
21 year ago
scare preview

scare

GitHubnetspooky/scare

A multi-arch assembly REPL and emulator for your command line.

binary-analysisdebuggersdynamic-analysis-sandboxing+4
3111 year ago
ManualRsrcDataFetching preview

ManualRsrcDataFetching

GitHubnul0x4c/manualrsrcdatafetching

Get your data from the resource section manually, with no need for windows apis

binary-analysispayload-developmentred-teaming+1
671 year ago
DrayTek-Exploit preview

DrayTek-Exploit

GitHubsymbolexe/draytek-exploit

CVE-2022-23093 FreeBSD Stack-Based Overflow

binary-exploitationexploitationpayload-development+3
2 years ago
AlanFramework preview

AlanFramework

GitHubenkomio/alanframework

A C2 post-exploitation framework

command-and-controlencryption-decryption-toolslateral-movement+7
4862 years ago
dvenom preview
Archived

dvenom

GitHubzerx0r/dvenom

🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.

encryption-decryption-toolsexploitationpayload-development+4
1582 years ago
CVE-2020-8644-PlaySMS-1.4 preview

CVE-2020-8644-PlaySMS-1.4

GitHubh3rm1tr3b0rn/cve-2020-8644-playsms-1.4

Python script to exploit PlaySMS before 1.4.3

exploitationpayload-generationpenetration-testing+3
23 years ago
Shellcrypt preview

Shellcrypt

GitHubiilegacyyii/shellcrypt

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

cryptographyencryption-decryption-toolspayload-development+3
2173 years ago
EXOCET-AV-Evasion preview

EXOCET-AV-Evasion

GitHubtanc7/exocet-av-evasion

EXOCET - AV-evading, undetectable, payload delivery tool

command-and-controlcryptographyeducation+9
8374 years ago
WAMpage preview

WAMpage

GitHubdavidbuchanan314/wampage

WAMpage - A WebOS root LPE exploit chain (CVE-2022-23731)

binary-exploitationembedded-systems-securityexploitation+5
494 years ago
PEzor-Docker preview

PEzor-Docker

GitHubcyb3r-techie/pezor-docker

With the help of this docker image, you can easily access PEzor on your system!

educationexploitationpayload-generation+2
154 years ago
Beaconator preview

Beaconator

GitHubcapt-meelo/beaconator

A beacon generator using Cobalt Strike and a variety of tools.

command-and-controlexploit-frameworkspayload-generation+2
4465 years ago
Previous12Next