Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Payload Development

Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

NewestRelevanceMost popularRecently updated
3296 results
TangledWinExec preview

TangledWinExec

GitHubdaem0nc0re/tangledwinexec

PoCs and tools for investigation of Windows process execution techniques

ids-ips-evasionreverse-engineeringshellcode+6
9586 months ago
NiCOFF preview

NiCOFF

GitHubfrkngksl/nicoff

COFF and BOF Loader written in Nim

post-exploitationpenetration-testingred-teaming+1
1774 months ago
POC-CVE-2017-8464-OpenCalculator preview

POC-CVE-2017-8464-OpenCalculator

GitHubplayboisk8/poc-cve-2017-8464-opencalculator

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

vulnerability-analysisexploitationbinary-analysis+2
12 days ago
Shellcrypt preview

Shellcrypt

GitHubiilegacyyii/shellcrypt

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

encryption-decryption-toolspayload-generationshellcode+3
2163 years ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubdungsocool/cve-2026-64638

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

phishing-toolsvulnerability-analysiscode-analysis+4
12 days ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubjendmaoul/xss2shell-cve-2026-64638

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

exploitationweb-application-exploitationpost-exploitation+4
113 days ago
log4j-shell-poc preview

log4j-shell-poc

GitHubjiahong-guan/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

payload-generationexploitationweb-application-exploitation+3
112 days ago
Root-My-Galaxy preview

Root-My-Galaxy

GitHubruik-tech/root-my-galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

android-securityprivilege-escalationexploitation+2
12 days ago
CVE-2026-63077 preview

CVE-2026-63077

GitHubanggatechi/cve-2026-63077

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…

exploitationweb-application-exploitationweb-security+2
13 days ago
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

shellcodepost-exploitationred-teaming+1
5132 years ago
NoFaxGiven preview

NoFaxGiven

GitHubhackerhouse-opensource/nofaxgiven

Code Execution & Persistence in NETWORK SERVICE FAX Service

privilege-escalationpersistence-mechanismsexploitation+3
376 months ago
CVE-2026-64638 preview

CVE-2026-64638

GitHub4minx/cve-2026-64638

Single-file HTML proof-of-concept for WordPress pre-auth reflected XSS (CVE-2026-64638), demonstrating unauthenticated JavaScript execution and an…

vulnerability-analysisexploitationweb-application-exploitation+3
113 days ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

vulnerability-scannersexploitationweb-application-exploitation+3
213 days ago
PowerSploit preview

PowerSploit

GitHubzerodaylab/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

penetration-testing-frameworksprivilege-escalationreconnaissance+7
2394 years ago
rust_syscalls preview

rust_syscalls

GitHubjanoglezcampos/rust_syscalls

Single stub direct and indirect syscalling with runtime SSN resolving for windows.

ids-ips-evasionpost-exploitationred-teaming+1
2403 years ago
Heroinn preview

Heroinn

GitHubb23r0/heroinn

A cross platform C2/post-exploitation framework.

penetration-testing-frameworkspost-exploitationcommand-and-control+4
7123 years ago
SharpWhispers preview

SharpWhispers

GitHubsecforce/sharpwhispers

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

ids-ips-evasionshellcodepost-exploitation+2
1123 years ago
GwisinMsi preview

GwisinMsi

GitHubchoisg/gwisinmsi

PoC MSI payload based on ASEC/AhnLab's blog post

malware-analysisred-teamingpayload-development+1
253 years ago
Previous1…567…184Next