Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
85 results
CVE-2012-2982 preview

CVE-2012-2982

GitHubostojaofficial/cve-2012-2982

Python exploit for CVE-2012-2982

command-and-controlexploitationpenetration-testing+2
2
5 years ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubbyteforgefr/cve-2011-2523

VsFTPd 2.3.4 Backdoor Command Execution

command-and-controlexploitationpayload-generation+3
13 months ago
google_socks preview
Archived

google_socks

GitHublukebaggett/google_socks

A proof of concept demonstrating the use of Google Drive for command and control.

cloud-securitycommand-and-controldata-exfiltration+3
888 years ago
malvinci preview

malvinci

GitHubxgrxmey/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controlpayload-developmentremote-access-trojan
591 year ago
ycsm preview

ycsm

GitHubinfosecn1nja/ycsm

This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools…

anti-botcommand-and-controlids-ips-evasion+2
867 years ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubchristian93111/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authenticationcommand-and-controleducation+6
103 months ago
jboss-autopwn preview

jboss-autopwn

GitHubgitcollect/jboss-autopwn

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

command-and-controlexploitationpayload-development+4
110 years ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubaratane/cve-2024-9474

Palo Alto RCE Vuln

command-and-controlexploitationpenetration-testing+3
11 year ago
CVE-2024-28397-Js2Py-RCE preview

CVE-2024-28397-Js2Py-RCE

GitHuby0naldez/cve-2024-28397-js2py-rce

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

command-and-controlexploitationpayload-generation+3
3 months ago
chromebackdoor preview
Archived

chromebackdoor

GitHubgraniet/chromebackdoor

Chromebackdoor is a PoC of pentest tool, this tool use a MITB technique for generate a windows executable ".exe" after launch run a malicious…

command-and-controlpayload-generationpenetration-testing+2
5139 years ago
Malleable-C2-Randomizer preview

Malleable-C2-Randomizer

GitHubbluscreenofjeff/malleable-c2-randomizer

A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls

command-and-controlexploit-frameworksids-ips-evasion+3
4543 years ago
jboss-autopwn preview
Archived

jboss-autopwn

GitHubspiderlabs/jboss-autopwn

A JBoss script for obtaining remote shell access

command-and-controlexploitationpayload-generation+4
1776 years ago
CVE-2023-24489-ShareFile preview

CVE-2023-24489-ShareFile

GitHubadhikara13/cve-2023-24489-sharefile

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

command-and-controlexploitationpenetration-testing+3
133 years ago
CVE-2024-41570 preview

CVE-2024-41570

GitHubdiemoeve/cve-2024-41570

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

command-and-controlexploitationpayload-generation+5
121 year ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubthemehackers/cve-2024-10914

CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.

command-and-controleducationexploitation+4
91 year ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubpayatu/cve-2017-5638

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

command-and-controlexploitationpenetration-testing+3
89 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubprelearn-code/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

command-and-controlexploitationpayload-development+4
22 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubshamo0/cve-2022-1388

BIG-IP iControl REST vulnerability CVE-2022-1388 PoC

command-and-controlexploitationpenetration-testing+3
14 years ago
Previous12345Next