Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
65 results
xll_windows_reverse_shell preview

xll_windows_reverse_shell

GitHubh3x0v3rl0rd/xll_windows_reverse_shell

xll windows reverse shell

command-and-controlexploitationpayload-development+4
1 year ago
CVE-2026-39808 preview

CVE-2026-39808

GitHubsamu-delucas/cve-2026-39808

PoC for Unauthenticated RCE in FortiSandbox via CVE-2026-39808

command-and-controlexploitationpenetration-testing+2
94 months ago
cve-2023-0669-simulation preview

cve-2023-0669-simulation

GitHubzakaria-laouani/cve-2023-0669-simulation
command-and-controldata-exfiltrationexploitation+3
7 months ago
Absolutely-Positively-NOT-Hacking-Back-with-Pcap preview

Absolutely-Positively-NOT-Hacking-Back-with-Pcap

GitHubstvemillertime/absolutely-positively-not-hacking-back-with-pcap

Streaming Unexpected Network Byte Sequences with High Probability of Blue Screening or Otherwise Crashing Attacker Command-and-Control Nodes

command-and-controlexploitationids-ips-evasion+3
227 years ago
BlockchainC2 preview

BlockchainC2

GitHubxpn/blockchainc2

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

command-and-controlexploitationpayload-development+2
797 years ago
printerbugnew preview

printerbugnew

GitHubdecoder-it/printerbugnew

The DCERPC only printerbug.py version

authenticationcommand-and-controlexploitation+5
2349 months ago
CVE-2021-22123 preview

CVE-2021-22123

GitHubmurataydemir/cve-2021-22123

[CVE-2021-22123] Fortinet FortiWeb Authenticated OS Command Injection

command-and-controlexploitationpayload-development+3
65 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubschooldropout1337/cve-2024-3400
command-and-controlexploitationpayload-generation+3
42 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubshamo0/cve-2022-1388

BIG-IP iControl REST vulnerability CVE-2022-1388 PoC

command-and-controlexploitationpenetration-testing+3
14 years ago
SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2 preview

SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2

GitHubdevinliggins14/smb-pentest-exploiting-cve-2007-2447-on-metasploitable-2
command-and-controldata-exfiltrationeducation+6
1 year ago
ShockZaum-CVE-2014-6271 preview

ShockZaum-CVE-2014-6271

GitHubw4fz5uck5/shockzaum-cve-2014-6271

Shellshock vulnerability attacker

command-and-controlexploitationpenetration-testing+2
8 years ago
Log4Shell-CVE-2021-44228-PoC preview

Log4Shell-CVE-2021-44228-PoC

GitHubpierpaolosestito-dev/log4shell-cve-2021-44228-poc

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

command-and-controlexploitationpayload-development+3
13 years ago
CVE-2026-11834 preview

CVE-2026-11834

GitHubmattgsys/cve-2026-11834

Proof of Concept (PoC) for the TP-Link DHCP Option 66 Unauthenticated RCE (CVE-2026-11834)

command-and-controlexploitationpayload-generation+3
31 month ago
Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter preview

Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter

GitHubmrcl0wnlab/nuclei-template-exploit-f5-big-ip-icontrol-rest-auth-bypass-rce-command-parameter

CVE-2022-1388 is an authentication bypass vulnerability in the REST component of BIG-IP’s iControl API that was assigned a CVSSv3 score of…

command-and-controlexploitationpayload-generation+3
64 years ago
CVE-2025-58180 preview

CVE-2025-58180

GitHubprabhatverma47/cve-2025-58180

In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses…

command-and-controlexploitationpayload-generation+3
11 months ago
CVE-2025-47812 preview

CVE-2025-47812

GitHubr0otk3r/cve-2025-47812
command-and-controlexploitationpenetration-testing+3
21 year ago
CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC preview

CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

GitHubomer-efe-curkus/cve-2025-32433-erlang-otp-ssh-rce-poc

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

command-and-controlexploitationnetwork-security+3
161 year ago
CVE-2025-31644 preview

CVE-2025-31644

GitHubmbadanoiu/cve-2025-31644

CVE-2025-31644: Command Injection in Appliance mode in F5 BIG-IP

command-and-controlexploitationpenetration-testing+3
241 year ago
Previous1234Next