Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
111 results
dicerosbicornis preview

dicerosbicornis

GitHubmaldevel/dicerosbicornis

A fully featured Windows backdoor that uses email as a C&C server

command-and-controldata-exfiltrationencryption-decryption-tools+5
16
9 years ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub0x00jeff/cve-2025-27591

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

binary-exploitationexploitationpayload-development+5
151 month ago
CVE-2026-43499-aristotle-apk preview

CVE-2026-43499-aristotle-apk

GitHubsoralis0912/cve-2026-43499-aristotle-apk

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…

android-securitybinary-exploitationexploitation+5
527 days ago
CVE-2022-0847_dirty-pipe preview

CVE-2022-0847_dirty-pipe

GitHubludovicpatho/cve-2022-0847_dirty-pipe

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

binary-exploitationexploitationpayload-development+3
104 years ago
sc2elf preview

sc2elf

GitHubdump-guy/sc2elf

Simple dotnet Native AOT app that uses LibObjectFile to convert shellcode to ELF

binary-analysismalware-analysisreverse-engineering+1
103 years ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
CVE-2025-3243 preview

CVE-2025-3243

GitHubtenebrae93/cve-2025-3243

A proof-of-concept exploit for CVE-2025-32433, a critical vulnerability in Erlang's SSH library that allows pre-authenticated code execution via…

exploitationpayload-generationpenetration-testing+3
71 year ago
Notepad-8.8.1_CVE-2025-49144 preview

Notepad-8.8.1_CVE-2025-49144

GitHubb0ysie7e/notepad-8.8.1_cve-2025-49144

Proof of Concept (PoC) that exploits the CVE-2025-49144 vulnerability in the Notepad++ 8.8.1 installer.

binary-exploitationeducationexploitation+3
61 year ago
CVE-2022-0847-container-escape preview

CVE-2022-0847-container-escape

GitHubjlsakuya/cve-2022-0847-container-escape

A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.

container-escapeexploitationpayload-generation+3
23 years ago
Rig-Exploit-for-CVE-2018-8174 preview

Rig-Exploit-for-CVE-2018-8174

GitHuborf53975/rig-exploit-for-cve-2018-8174

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

command-and-controlexploitationmalware-analysis+3
8 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubmr-r00t11/cve-2024-23692

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

exploitationpayload-generationpenetration-testing+4
2 years ago
chamilo-lms-unauthenticated-rce-poc preview

chamilo-lms-unauthenticated-rce-poc

GitHubcharchit-subedi/chamilo-lms-unauthenticated-rce-poc

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

exploitationpayload-generationpenetration-testing+3
2 years ago
Anti_suspend preview

Anti_suspend

GitHubgmh5225/anti_suspend

Shellcode-based process protection that prevents thread suspension, blocks debugger attach, masks hardware breakpoints, and hides threads from…

defensive-toolsreverse-engineeringshellcode
53 years ago
dvenom preview
Archived

dvenom

GitHubzerx0r/dvenom

🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.

encryption-decryption-toolsexploitationpayload-development+4
1582 years ago
Mangle preview
Archived

Mangle

GitHuboptiv/mangle

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

binary-analysisdefensive-toolsexploitation+6
1.2k3 years ago
bash-4.3-fixed-CVE-2014-6271 preview

bash-4.3-fixed-CVE-2014-6271

GitHubu20024804/bash-4.3-fixed-cve-2014-6271
general-purpose-utilitiesscripting-automationshellcode+1
11 years ago
bash-3.2-fixed-CVE-2014-6271 preview

bash-3.2-fixed-CVE-2014-6271

GitHubu20024804/bash-3.2-fixed-cve-2014-6271
exploitationgeneral-purpose-utilitiespenetration-testing+2
11 years ago
pe_to_shellcode preview

pe_to_shellcode

GitHubhasherezade/pe_to_shellcode

Converts PE into a shellcode

binary-exploitationexploitationpayload-development+3
2.8k11 months ago
Previous1234567Next