Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Payload Generation

Tools for creating and customizing malicious code or instructions to execute after exploitation.

NewestRelevanceMost popularRecently updated
3374 results
TinyLoad preview

TinyLoad

GitHubiamsopotatoe-coder/tinyload

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

encryption-decryption-toolspayload-generationexploitation+5
180
9h 30m ago
penelope preview

penelope

GitHubbrightio/penelope

Penelope Shell Handler

payload-generationshellcodepost-exploitation+5
2.0k0 days ago
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

osintreconnaissancevulnerability-scanners+9
3.9k1 day ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

penetration-testing-frameworksexploit-frameworkspayload-generation+4
11.7k1 day ago
PAYLOAD-LISTS preview

PAYLOAD-LISTS

GitHubnu11secur1ty/payload-lists
payload-generationvulnerability-analysisweb-application-exploitation+3
41 day ago
PyIris preview

PyIris

GitHubnot-sekiun/pyiris

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

payload-generationexploitationpost-exploitation+4
3251 day ago
Cybersec preview

Cybersec

GitHubamitr12/cybersec
password-crackingprivilege-escalationreconnaissance+9
91 day ago
CVE-2025-24893_Analysis preview

CVE-2025-24893_Analysis

GitHubmattiacervelli/cve-2025-24893_analysis

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

payload-generationvulnerability-analysisexploitation+5
1 day ago
CVE-2026-47858 preview

CVE-2026-47858

GitHubrealstatus/cve-2026-47858

Proof-of-concept exploit for unauthenticated JMX RCE in Spring Tools live information mode, using MLet remote class loading to execute arbitrary…

payload-generationvulnerability-analysisexploitation+1
1 day ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

payload-generationvulnerability-analysisexploitation+4
1 day ago
CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization preview

CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization

GitHubcypherhippie/cve-2026-34486---unauthenticated-rce-via-java-deserialization

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

payload-generationvulnerability-analysisexploitation+2
1 day ago
CVE-2026-19501-poc preview

CVE-2026-19501-poc

GitHubtypedefabcd1234ntd/cve-2026-19501-poc

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

payload-generationvulnerability-analysisexploitation+3
2 days ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

penetration-testing-frameworksprivilege-escalationreconnaissance+9
38.8k2 days ago
dyen preview

dyen

GitHubcenobyte-vincit/dyen

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

payload-generationids-ips-evasionpost-exploitation+4
2 days ago
Palimpsest preview

Palimpsest

GitHubdefineid/palimpsest

CVE-2026-74945 · Uninitialized heap disclosure via a crafted web font (sec-high)

payload-generationvulnerability-analysisexploitation+1
3 days ago
AddUser-SAMR preview

AddUser-SAMR

GitHubricardojoserf/adduser-samr

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

privilege-escalationpayload-generationpersistence-mechanisms+5
953 days ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

vulnerability-scannerspayload-generationport-scanning+6
13 days ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubnowafen/cve-2026-16723

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

payload-generationexploitationweb-application-exploitation+2
24 days ago
Previous12…188Next