Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
133 results
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
39.0k15h 12m ago
Graffiti preview

Graffiti

GitHubekultek/graffiti

A tool to generate obfuscated one liners to aid in penetration testing

payload-developmentpayload-generationpenetration-testing+1
1807 years ago
linux_injector preview

linux_injector

GitHubnamazso/linux_injector

A simple ptrace-less shared library injector for x64 Linux

adversarial-attackpayload-developmentpenetration-testing+3
2953 years ago
asminject preview

asminject

GitHubbishopfox/asminject

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

container-escapepayload-developmentpenetration-testing+2
1493 years ago
malasada preview

malasada

GitHubsliverarmory/malasada

Linux Shared Library to Shellcode Loader

binary-exploitationexploitationpayload-development+5
1027 months ago
CVE-2025-60751 preview

CVE-2025-60751

GitHubkaleth4/cve-2025-60751

Technical analysis and professional exploit for CVE-2025-60751, a stack-based buffer overflow in GeographicLib. Includes a pwntools-based Ret2Libc…

binary-exploitationdebuggerseducation+6
4 months ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubyassdev221608/cve-2024-6387

Python exploit for CVE-2024-6387 (OpenSSH signal handler race condition) targeting glibc-based 32-bit Linux systems, with multi-threaded concurrency…

binary-exploitationexploitationpayload-development+3
1 year ago
penelope preview

penelope

GitHubbrightio/penelope

Penelope Shell Handler

command-and-controlctfpayload-generation+5
2.1k12 days ago
harpyTools preview

harpyTools

GitHubjssngc/harpytools

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

command-and-controlexploitationlateral-movement+6
2012 days ago
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
223 days ago
baron-samedit preview

baron-samedit

GitHubczeti/baron-samedit

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

binary-exploitationexploitationpayload-development+4
1 year ago
PEzor preview

PEzor

GitHubphra/pezor

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

exploit-frameworksids-ips-evasionpayload-generation+3
2.1k2 years ago
Chankro preview

Chankro

GitHubtarlogicsecurity/chankro

Herramienta para evadir disable_functions y open_basedir

exploitationpayload-developmentpenetration-testing+3
4957 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubl0n3m4n/cve-2024-6387

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

exploitationnetwork-securitypayload-development+6
1132 years ago
staekka preview

staekka

GitHubj-0-t/staekka

Stækka Metasploit - Extenting Metasploit

anti-botexploit-frameworksforensics+7
549 years ago
gopher47 preview

gopher47

GitHuban00brektn/gopher47

A third-party Gopher Assassin for the Havoc Framework.

command-and-controlpenetration-testingport-scanning+4
442 years ago
PhantomEvasion preview

PhantomEvasion

GitHubesskumar/phantomevasion

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

exploit-frameworkspayload-generationpenetration-testing+5
176 years ago
CVE-2026-43499-aristotle-apk preview

CVE-2026-43499-aristotle-apk

GitHubsoralis0912/cve-2026-43499-aristotle-apk

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…

android-securitybinary-exploitationexploitation+5
41 month ago
Previous12…8Next