Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
Social-media-c2 preview

Social-media-c2

GitHubwoj-ciech/social-media-c2

Script is a proof of concept how to control your machine by using social media sites.

command-and-controlinformation-gatheringosint-social-engineering+3
23
8 years ago
Kernel-Process-Hollowing preview
Archived

Kernel-Process-Hollowing

GitHubxaff-xaff/kernel-process-hollowing

Windows x64 kernel mode rootkit process hollowing POC.

ids-ips-evasionpayload-developmentpost-exploitation+1
1933 years ago
hinge-command-control-c2 preview

hinge-command-control-c2

GitHubmatthewwiese/hinge-command-control-c2

A proof of concept demonstrating how to use the Hinge dating app as a C2.

command-and-controlosintpenetration-testing+3
119 months ago
dh-CVE_2016_2098 preview

dh-CVE_2016_2098

GitHubhderms/dh-cve_2016_2098

Proof of concept showing how CVE-2016-2098 leads to remote code execution

educationexploitationpenetration-testing+2
310 years ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubthemehackers/cve-2025-54100

CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

educationexploitationpapers-research+3
319 months ago
bl_sbx preview

bl_sbx

GitHubhanakim3945/bl_sbx

itunesstored & bookassetd sbx escape

binary-exploitationeducationexploitation+3
32710 months ago
claude-code-backdoor preview

claude-code-backdoor

GitHubs0ld13rr/claude-code-backdoor

Backdooring Claude Code via hooks in settings.json. Authorized use only!

educationmalware-analysispenetration-testing+4
885 months ago
Dirty-Frag-Kubernetes-PoC preview

Dirty-Frag-Kubernetes-PoC

GitHubpercivalll/dirty-frag-kubernetes-poc

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

cloud-securitycontainer-escapeexploitation+3
165 months ago
Copy-Fail-CVE-2026-31431-Kubernetes-PoC preview

Copy-Fail-CVE-2026-31431-Kubernetes-PoC

GitHubstarscow/copy-fail-cve-2026-31431-kubernetes-poc

Proof-of-concept demonstrating container escape on Kubernetes via CVE-2026-31431 kernel page-cache corruption, achieving node-level code execution…

container-escapeeducationexploitation+2
5 months ago
mysslstrip preview
Archived

mysslstrip

GitHubduo-labs/mysslstrip

Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.

database-securityexploitationids-ips-evasion+3
4311 years ago
CVE-2024-4323-Exploit-POC preview

CVE-2024-4323-Exploit-POC

GitHubskilfoy/cve-2024-4323-exploit-poc

This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code…

exploitationpayload-generationpenetration-testing+3
152 years ago
CVE-2025-29927-Nextjs-Bypass-PoC preview

CVE-2025-29927-Nextjs-Bypass-PoC

GitHubdanielhallbro/cve-2025-29927-nextjs-bypass-poc

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

authenticationeducationexploitation+3
18 months ago
IFA preview

IFA

GitHubjofpin/ifa

PoC exposing a critical IndexedDB vulnerability that enables a disk flooding attack by exploiting the lack of restrictions.

educationexploitationvulnerability-analysis+1
282 years ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubygouzerh/cve-2017-12617

Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018

educationexploitationpayload-generation+3
27 years ago
LocalStranger preview

LocalStranger

GitHubnbs32k/localstranger

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

binary-exploitationexploit-frameworkspayload-development+3
3715 days ago
ClearML-CVE-2024-24590 preview

ClearML-CVE-2024-24590

GitHuboxydev2/clearml-cve-2024-24590

Proof of concept for CVE-2024-24590

ai-securityexploitationpayload-generation+3
62 years ago
CVE-2026-25940 preview

CVE-2026-25940

GitHubopen-flaw/cve-2026-25940

Proof-of-concept for CVE-2026-25940 demonstrating embedded JavaScript execution via crafted AcroForm radio button appearances in PDF viewers, with…

exploitationpayload-generationvulnerability-analysis+2
7 months ago
CVE-2022-42889-POC preview

CVE-2022-42889-POC

GitHubakshayithape-devops/cve-2022-42889-poc

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

educationexploitationlabs-practice+3
53 years ago
Previous12Next