Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
39
10 days ago
poc-CVE-2026-64638- preview

poc-CVE-2026-64638-

GitHubmohwahyudi/poc-cve-2026-64638-

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

exploitationpayload-generationpenetration-testing+5
1 month ago
CVE-2023-52076-PoC preview

CVE-2023-52076-PoC

GitHubgroppoxx/cve-2023-52076-poc

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

binary-exploitationexploitationpayload-generation+3
32 months ago
LnkMeMaybe preview

LnkMeMaybe

GitHubtrustedsec/lnkmemaybe

Lnk crafting and research tools

binary-analysisdigital-forensicsexploitation+3
1856 months ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdionissh/cve-2024-21413

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

email-securityexploitationpassword-cracking+3
8 months ago
Facad1ng preview

Facad1ng

GitHubspyboy-productions/facad1ng

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

defensive-toolseducationphishing+3
5238 months ago
CVE-2010-1240 preview
Archived

CVE-2010-1240

GitHub12345qwert123456/cve-2010-1240

Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions

educationexploitationpayload-generation+3
1 year ago
oauthseeker preview

oauthseeker

GitHubpraetorian-inc/oauthseeker

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

authenticationcloud-securityidentity-access-management+6
1801 year ago
CVE-2025-33053-Proof-Of-Concept preview

CVE-2025-33053-Proof-Of-Concept

GitHubdevbuihieu/cve-2025-33053-proof-of-concept

CVE-2025-33053 Proof Of Concept (PoC)

command-and-controlexploitationlateral-movement+6
631 year ago
FakeImageExploiter preview

FakeImageExploiter

GitHubr00t-3xp10it/fakeimageexploiter

Use a Fake image.jpg to exploit targets (hide known file extensions)

command-and-controlexploitationpayload-development+5
9481 year ago
CVE-2025-3568 preview

CVE-2025-3568

GitHubshellkraft/cve-2025-3568

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

exploitationphishingprivilege-escalation+3
1 year ago
boobsnail preview

boobsnail

GitHubstmcyber/boobsnail

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

payload-generationpenetration-testingphishing-tools+2
2551 year ago
CVE-2023-38873-G1 preview

CVE-2023-38873-G1

GitHubk9-modz/cve-2023-38873-g1

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

educationexploitationpapers-research+3
1 year ago
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
31 year ago
CVE-2025-23040 preview

CVE-2025-23040

GitHubgabrieledattile/cve-2025-23040

Proof-of-concept exploit for CVE-2025-23040 demonstrating credential exfiltration from GitHub Desktop (< 3.4.12) via malicious repository clone URLs,…

exploitationinformation-gatheringsocial-engineering+2
1 year ago
Cuteit preview

Cuteit

GitHubd4vinci/cuteit

IP obfuscator made to make a malicious ip a bit cuter

command-and-controlids-ips-evasionpayload-generation+4
5461 year ago
CVE-2023-38831-Exploit preview

CVE-2023-38831-Exploit

GitHubtechnicalcorp0/cve-2023-38831-exploit

This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a…

educationexploitationpayload-generation+4
11 year ago
macro_pack preview
Archived

macro_pack

GitHubsevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exploit-frameworkslateral-movementpayload-generation+6
2.3k2 years ago
Previous123Next