#1General-purpose tools, frameworks, and environments supporting various cybersecurity workflows and tasks.
Kitploit recommended

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…
Docker image packaging a proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel privilege escalation vulnerability.

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

Woeful is a tool that lets web apps to safely and securely connect to the outside internet without a complex backend.

A collection of exploits for different VoIP products.

A powerfull websites compiler/obfuscator for optimization or intellectual property protection purposes.

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Automate Metasploit scanning and exploitation

Exploit para explotar la vulnerabilidad CVE-2025-32463

REST/JSON API to the Burp Suite security tool.

Remote code execution exploit for Wazuh 8.4 (CVE-2025-24016) with Python-based proof-of-concept targeting vulnerable SIEM deployments.

Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE

Manual and automated exploitation walkthrough for vsftpd 2.3.4 backdoor (CVE-2011-2523) with custom reverse shell payload and Metasploit integration…

ARCHIVED: FBC v2 consulting website draft. Deprecated. Vulnerable to CVE-2026-44579 (Next.js Cache DoS).

Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate…