Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
427 results
micr0_shell preview

micr0_shell

GitHubsenzee1984/micr0_shell

micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.

exploitationpayload-developmentpayload-generation+2
224
5 months ago
CVE-2025-15403 preview

CVE-2025-15403

GitHubnxploited/cve-2025-15403

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

exploitationpayload-developmentpenetration-testing+5
5 months ago
BlueSAM preview

BlueSAM

GitHubincursi0n/bluesam

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

command-and-controlexploitationpayload-development+3
1675 months ago
CVE-2024-26229-BOF preview

CVE-2024-26229-BOF

GitHub0xgunrunner/cve-2024-26229-bof

CVE-2024-26229 Beacon Object File version

binary-exploitationexploitationpayload-development+4
5 months ago
CVE-2025-66849 preview

CVE-2025-66849

GitHubwojtekchwala/cve-2025-66849

Ghost CMS Privilege Escalation PoC

exploitationpayload-developmentpenetration-testing+3
5 months ago
DsArk64 preview

DsArk64

GitHubgmh5225/dsark64

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…

binary-exploitationdefensive-toolsexploitation+6
125 months ago
CVE-2025-81110-PoC preview

CVE-2025-81110-PoC

GitHubbridgeralderson/cve-2025-81110-poc

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

exploitationpayload-developmentpenetration-testing+4
45 months ago
CTT-Vsyslog-Vortex-CVE-2023-6246 preview

CTT-Vsyslog-Vortex-CVE-2023-6246

GitHubsimoesctt/ctt-vsyslog-vortex-cve-2023-6246

CVE-2023-6246 glibc __vsyslog_internal() heap buffer overflow exploitation using Convergent Time Theory (α = 0.0302011). 33-layer temporal heap spray…

binary-exploitationexploitationpayload-development+3
5 months ago
HintInject preview

HintInject

GitHubfrkngksl/hintinject

A PoC project for embedding shellcode to Hint/Name Table

binary-analysisexploitationpayload-development+3
1145 months ago
NiCOFF preview

NiCOFF

GitHubfrkngksl/nicoff

COFF and BOF Loader written in Nim

payload-developmentpenetration-testingpost-exploitation+1
1785 months ago
CVE-2025-62429 preview

CVE-2025-62429

GitHubdrkim-dev/cve-2025-62429

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

code-analysisexploitationpayload-development+5
15 months ago
CVE-2025-54123-Poc preview

CVE-2025-54123-Poc

GitHubkasem545/cve-2025-54123-poc

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

command-and-controlexploitationpayload-development+5
75 months ago
CVE-2026-24291 preview

CVE-2026-24291

GitHublennertdefauw/cve-2026-24291

Obfuscated Windows privilege escalation exploit for CVE-2026-24291 that automatically creates a local administrator with generated credentials.

exploitationpayload-developmentpost-exploitation+1
46 months ago
Nagios-CVE-2019-15949-RCE preview

Nagios-CVE-2019-15949-RCE

GitHubplur1bu5/nagios-cve-2019-15949-rce

a PoC for the Nagios CVE-2019-15949 rce in python

exploitationpayload-developmentpenetration-testing+3
6 months ago
ZeroHVCI preview

ZeroHVCI

GitHubzer0condition/zerohvci

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

binary-exploitationexploitationpayload-development+2
2936 months ago
PEREDBOEMPATAT-BOF preview

PEREDBOEMPATAT-BOF

GitHubtailoredsecops/peredboempatat-bof

LocalPotato NTLM reflection exploit (CVE-2023-21746) as a Cobalt Strike Beacon Object File

exploitationpayload-developmentpenetration-testing+2
16 months ago
zig-pe preview

zig-pe

GitHubthoxy67/zig-pe

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

binary-exploitationexploitationpayload-development+3
656 months ago
NachoVPN preview

NachoVPN

GitHubamberwolfcyber/nachovpn

A delicious, but malicious SSL-VPN server 🌮

adversarial-attackexploitationnetwork-security+5
2696 months ago
Previous1…456…24Next