Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
271 results
TinyLoad preview

TinyLoad

GitHubiamsopotatoe-coder/tinyload

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

binary-analysisencryption-decryption-toolsexploitation+5
185
4 days ago
mkPIVM preview

mkPIVM

GitHubd7ead/mkpivm

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

exploitationmalware-analysispayload-generation+3
41310 days ago
Fritter preview

Fritter

GitHub0xrootpls/fritter

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

binary-exploitationexploitationpayload-development+5
24920 days ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubjenderal92/cve-2026-48908

Multi-threaded PoC exploit for unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload. Features case-bypass, shell verification, and…

exploitationpayload-generationpenetration-testing+4
31 month ago
CVE-2024-36401 preview

CVE-2024-36401

GitHubkeelanbrady1011/cve-2024-36401

CVE-2024-36401 exploit with webshell-like functionality for limited environments, supporting self-signed TLS sessions and remote command execution…

exploitationpayload-generationremote-access-tool+2
1 month ago
lacuna-rs preview

lacuna-rs

GitHubkarkas66/lacuna-rs

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

binary-exploitationpayload-developmentpost-exploitation+2
181 month ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub0x00jeff/cve-2025-27591

Exploits CVE-2025-27591 local privilege escalation using a symlink on a world-writable log file to inject /etc/ld.so.preload and spawn a root reverse…

binary-exploitationexploitationpayload-development+5
151 month ago
DirtyClone preview

DirtyClone

GitHubgl1tch0x1/dirtyclone

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

binary-exploitationcryptographyexploitation+3
31 month ago
CVE-2026-48908-SP-Page-Builder-Joomla preview

CVE-2026-48908-SP-Page-Builder-Joomla

GitHubgagaltotal/cve-2026-48908-sp-page-builder-joomla

Go-based proof-of-concept exploit for CVE-2026-48908, enabling unauthenticated remote code execution on Joomla SP Page Builder via malicious ZIP…

command-and-controlexploitationpayload-development+6
2 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubwearehackers160/cve-2026-48907

Python exploit and Nuclei template for CVE-2026-48907, a critical Joomla JCE editor access control flaw enabling unauthenticated PHP file upload and…

exploitationpayload-generationpenetration-testing+3
2 months ago
CVE-2026-11645 preview

CVE-2026-11645

GitHubadamshaikhma/cve-2026-11645

Exploit for CVE-2026-11645, a V8 out-of-bounds read/write in Google Chrome allowing remote code execution via crafted HTML pages.

binary-exploitationexploitationpayload-generation+3
2 months ago
Maverick preview

Maverick

GitHubblacksnufkin/maverick

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

binary-analysiscommand-and-controlencryption-decryption-tools+5
1142 months ago
CVE-2023-46604-RCE preview

CVE-2023-46604-RCE

GitHubreggyraider/cve-2023-46604-rce

Python exploit for Apache ActiveMQ CVE-2023-46604 unauthenticated remote code execution with Linux reverse shell payload delivery via XML…

exploitationpayload-generationremote-access-tool+3
2 months ago
CVE-2026-31431-Copy-Fail preview

CVE-2026-31431-Copy-Fail

GitHubt1ckprivate/cve-2026-31431-copy-fail

Pre-compiled exploit for CVE-2026-31431 (Copy Fail) with multi-architecture binary builds for x86_64, i386, aarch64, armv7, riscv64, ppc64le, and…

binary-exploitationexploitationpayload-generation+2
2 months ago
CVE-2026-43284-Dirty-Frag preview

CVE-2026-43284-Dirty-Frag

GitHubt1ckprivate/cve-2026-43284-dirty-frag

Pre-compiled exploit for CVE-2026-43284 (Dirty Frag) with multi-architecture support (x86_64, i386, aarch64, armv7, riscv64, ppc64le, s390x).…

binary-exploitationexploitationpayload-generation+2
2 months ago
Stardust preview

Stardust

GitHubcracked5pider/stardust

A modern 32/64-bit position independent implant template

binary-exploitationexploitationpayload-development+4
1.4k2 months ago
PinTheft-asm preview

PinTheft-asm

GitHubkoshmare-blossom/pintheft-asm

A x86_64 ASM implementation of PinTheft (CVE-2026-43494)

binary-exploitationexploitationpayload-development+3
12 months ago
copyfail-deconstructed preview

copyfail-deconstructed

GitHubbootsareme/copyfail-deconstructed

Educational deconstruction of CVE-2026-31431 privilege escalation exploit, providing readable Python and C implementations with custom shellcode…

binary-exploitationeducationexploitation+3
33 months ago
Previous12…16Next