Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
427 results
USP preview

USP

GitHubgrahamhelton/usp

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

payload-developmentpersistence-mechanismspost-exploitation+2
153
2 years ago
eop24-26229 preview
Archived

eop24-26229

GitHubcracked5pider/eop24-26229

A firebeam plugin that exploits the CVE-2024-26229 vulnerability to perform elevation of privilege from a unprivileged user

exploitationpayload-developmentpost-exploitation+1
412 years ago
koppeling-p preview

koppeling-p

GitHubklezvirus/koppeling-p

Adaptive DLL hijacking / dynamic export forwarding - EAT preserve

binary-exploitationexploitationpayload-development+3
792 years ago
Brute-Ratel-C4-Community-Kit preview

Brute-Ratel-C4-Community-Kit

GitHubparanoidninja/brute-ratel-c4-community-kit

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

command-and-controlexploitationpayload-development+3
3052 years ago
MASS-CVE-2024-27956 preview

MASS-CVE-2024-27956

GitHubitzheartzz/mass-cve-2024-27956

Proof-of-concept exploit for CVE-2024-27956 SQL injection in ValvePress Automatic plugin. Creates admin users in WordPress to achieve remote code…

exploitationpayload-developmentpenetration-testing+3
32 years ago
CVE-2023-51518 preview

CVE-2023-51518

GitHubmbadanoiu/cve-2023-51518

CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James

exploitationpayload-developmentpenetration-testing+3
12 years ago
TrollDump preview

TrollDump

GitHubcybersectroll/trolldump

Injects x64 managed DLLs into GUI processes via SetWindowsHook, with a modular C# payload runner and LSASS dump POC for red-team/offensive Windows…

payload-developmentpost-exploitationprivilege-escalation+1
842 years ago
PINKPANTHER preview

PINKPANTHER

GitHubwinterknife/pinkpanther

Windows x64 handcrafted token stealing kernel-mode shellcode

binary-exploitationpayload-developmentpost-exploitation+2
5192 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubmomika233/cve-2024-3400

Proof-of-concept exploit for CVE-2024-3400, demonstrating command injection in Palo Alto PAN-OS with a Python-based backdoor, persistence via…

command-and-controlexploitationmalware-analysis+4
132 years ago
CVE-2023-32233 preview

CVE-2023-32233

GitHubvoid0red/cve-2023-32233

Linux kernel privilege escalation exploit for CVE-2023-32233 using nft_quota UAF, ROP chain, and modprobe_path overwrite to gain root on kernels…

binary-exploitationexploitationpayload-development+3
12 years ago
rusty_drivers preview

rusty_drivers

GitHubflorianib/rusty_drivers

BYOVD collection

adversarial-attackexploitationids-ips-evasion+2
242 years ago
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

payload-developmentpost-exploitationred-teaming+1
5132 years ago
winsos-poc preview

winsos-poc

GitHubthiagopeixoto/winsos-poc

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

adversarial-attackexploitationpayload-development+2
1112 years ago
venom-rs preview
Archived

venom-rs

GitHubmemn0ps/venom-rs

Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom)

payload-developmentpost-exploitationred-teaming+2
3702 years ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1602 years ago
DotNET_XorCryptor preview

DotNET_XorCryptor

GitHubdosx-dev/dotnet_xorcryptor

A new simple and powerfull packer for malware

adversarial-attackcryptographypayload-development+1
1072 years ago
iberyanbytes preview

iberyanbytes

GitHubleviathanfromdeepsea/iberyanbytes

PowerShell-based Active Directory enumeration tool for gathering network configuration, domain objects, user sessions, share permissions, and…

information-gatheringpassword-attackspenetration-testing+2
2 years ago
CVE-2021-1675-CVE-2021-34527 preview

CVE-2021-1675-CVE-2021-34527

GitHubwhoami-chmod777/cve-2021-1675-cve-2021-34527

PowerShell exploit for PrintNightmare (CVE-2021-1675) performing local privilege escalation via Print Spooler, with custom DLL payload injection to…

binary-exploitationexploitationpayload-development+2
12 years ago
Previous1…101112…24Next