Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
shadow preview

shadow

GitHubcensus/shadow

jemalloc heap exploitation framework

binary-exploitationdebuggersexploitation+2
4694 years ago
Januscape preview

Januscape

GitHubv4bel/januscape

KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

binary-exploitationcloud-securityexploitation+4
5721 month ago
anamnesis-release preview

anamnesis-release

GitHubseanheelan/anamnesis-release

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

ai-securitybinary-exploitationeducation+9
6338 months ago
Zapscape preview

Zapscape

GitHubv4bel/zapscape

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

binary-exploitationcloud-securityexploitation+3
1661 month ago
windows_kernel_shadow_stack preview

windows_kernel_shadow_stack

GitHubsynacktiv/windows_kernel_shadow_stack

Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.

binary-exploitationexploitationpapers-research+2
771 year ago
CVE-2026-64561 preview

CVE-2026-64561

GitHubhackspeak/cve-2026-64561

Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing

binary-exploitationexploitationred-teaming+2
21 month ago
CVE-2021-36934-HiveNightmare-Lab preview

CVE-2021-36934-HiveNightmare-Lab

GitHubd4yon/cve-2021-36934-hivenightmare-lab

Educational lab demonstrating CVE-2021-36934 (HiveNightmare) - Windows LPE via shadow copy ACL misconfiguration.

binary-exploitationeducationexploitation+4
17 months ago
CVE-2026-53359 preview

CVE-2026-53359

GitHub0xblackash/cve-2026-53359

CVE-2026-53359

binary-exploitationeducationexploitation+2
42 months ago
honda preview

honda

GitLabnu11secur1ty/0

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

binary-exploitationexploitationpayload-development+3
3 months ago
CVE-2020-17382 preview

CVE-2020-17382

GitHubtypeconfused/cve-2020-17382

CVE-2020-17382 Windows 10 x64 2004 Build 19041.264 Exploit

binary-exploitationexploitationprivilege-escalation+1
13 years ago
shadow preview

shadow

GitHubjoaoviictorti/shadow

Windows Kernel Rootkit in Rust

educationprivilege-escalation
71011 months ago
AutoRDPwn preview

AutoRDPwn

GitHubjoelgmsec/autordpwn

The Shadow Attack Framework

lateral-movementpassword-crackingpayload-generation+5
1.1k4 years ago
Zydra preview

Zydra

GitHubhameda2/zydra

Multi-threaded password recovery tool for RAR, ZIP, PDF, and Linux shadow files using dictionary and brute-force methods with configurable character…

data-recoverypassword-attackspassword-cracking
4346 years ago
noir preview

noir

GitHubowasp-noir/noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

api-securitydevsecopspenetration-testing+3
1.4k13h 23m ago
ACLight preview

ACLight

GitHubcyberark/aclight

A script for advanced discovery of Privileged Accounts - includes Shadow Admins

identity-access-managementprivilege-escalation
8307 years ago
Whisker preview

Whisker

GitHubeladshamir/whisker

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

authenticationexploitationpenetration-testing+4
9551 year ago
pywhisker preview

pywhisker

GitHubshutdownrepo/pywhisker

Python version of the C# tool for "Shadow Credentials" attacks

authenticationexploitationpenetration-testing+1
9413 months ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
41319 days ago
Previous123Next