Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
39
10 days ago
WhatsRCE preview

WhatsRCE

GitHubkeepwannabe/whatsrce

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

exploitationmobile-securitypayload-generation+3
775 years ago
poc-CVE-2026-64638- preview

poc-CVE-2026-64638-

GitHubmohwahyudi/poc-cve-2026-64638-

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

exploitationpayload-generationpenetration-testing+5
1 month ago
ImgBackdoor preview

ImgBackdoor

GitHubtsuyoken/imgbackdoor

Hide your payload into .jpg file

command-and-controlexploitationpayload-development+3
3944 years ago
LnkMeMaybe preview

LnkMeMaybe

GitHubtrustedsec/lnkmemaybe

Lnk crafting and research tools

binary-analysisdigital-forensicsexploitation+3
1856 months ago
RP_RecordClip_DLL_Hijack preview

RP_RecordClip_DLL_Hijack

GitHubedubr2020/rp_recordclip_dll_hijack

Remote DLL hijack exploit for Real Player (CVE-2022-32291) using malicious DLLs from WebDAV/SMB shares to achieve code execution.

binary-exploitationexploitationsocial-engineering
23 years ago
CVE-2023-52076-PoC preview

CVE-2023-52076-PoC

GitHubgroppoxx/cve-2023-52076-poc

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

binary-exploitationexploitationpayload-generation+3
32 months ago
Snoopy preview

Snoopy

GitHubsensepost/snoopy

Snoopy: A distributed tracking and data interception framework

malware-analysisnetwork-mappingosint+5
61213 years ago
C2 preview

C2

GitHubet0x/c2

Methods of C2

command-and-controlpayload-developmentpayload-generation+3
2111 years ago
oauthseeker preview

oauthseeker

GitHubpraetorian-inc/oauthseeker

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

authenticationcloud-securityidentity-access-management+6
1801 year ago
evil-winrar preview

evil-winrar

GitHubyoumulijiang/evil-winrar

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)

exploitationpayload-generationphishing-tools+3
112 years ago
WhatsRCE preview

WhatsRCE

GitHubjasonjerry/whatsrce

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

exploitationmobile-securitypayload-generation+3
46 years ago
CVE-2023-38873-G1 preview

CVE-2023-38873-G1

GitHubk9-modz/cve-2023-38873-g1

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

educationexploitationpapers-research+3
1 year ago
CVE-2025-3568 preview

CVE-2025-3568

GitHubshellkraft/cve-2025-3568

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

exploitationphishingprivilege-escalation+3
1 year ago
CVE-2025-33053-Proof-Of-Concept preview

CVE-2025-33053-Proof-Of-Concept

GitHubdevbuihieu/cve-2025-33053-proof-of-concept

CVE-2025-33053 Proof Of Concept (PoC)

command-and-controlexploitationlateral-movement+6
631 year ago
CVE-2025-23040 preview

CVE-2025-23040

GitHubgabrieledattile/cve-2025-23040

Proof-of-concept exploit for CVE-2025-23040 demonstrating credential exfiltration from GitHub Desktop (< 3.4.12) via malicious repository clone URLs,…

exploitationinformation-gatheringsocial-engineering+2
1 year ago
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
31 year ago
CVE-2023-38831-Exploit preview

CVE-2023-38831-Exploit

GitHubtechnicalcorp0/cve-2023-38831-exploit

This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a…

educationexploitationpayload-generation+4
11 year ago
Previous123Next