Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
483 results
PyIris preview

PyIris

GitHubnot-sekiun/pyiris

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

command-and-controlexploitationpayload-generation+4
327
5 days ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubalyaapm/cve-2025-55182-shellinteractive

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

command-and-controlexploitationpayload-generation+4
6 days ago
mcpExec preview

mcpExec

GitHubdaemoncibsec/mcpexec

POC for CVE-2026-23744 for a python revshell

command-and-controlexploitationpayload-generation+3
9 days ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
13 days ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubsandimfz/cve-2024-23692

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

command-and-controlexploitationpayload-generation+2
17 days ago
HTTP-Shell preview

HTTP-Shell

GitHubjoelgmsec/http-shell

Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

command-and-controlpayload-generationpenetration-testing+2
24319 days ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

adversarial-attackcommand-and-controleducation+9
1.1k21 days ago
Exch-CVE-2021-26855_Priv preview

Exch-CVE-2021-26855_Priv

GitHubzephrfish/exch-cve-2021-26855_priv

Exploit for Microsoft Exchange Server ProxyLogon (CVE-2021-26855) chained with CVE-2021-27065 to achieve unauthenticated remote code execution and…

command-and-controlexploitationpayload-generation+3
425 days ago
ScreenshotBOF preview

ScreenshotBOF

GitHubcodextf2/screenshotbof

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

command-and-controlpayload-developmentpenetration-testing+2
50727 days ago
hiphp preview

hiphp

GitHubyasserbdj96/hiphp

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

command-and-controlpayload-generationremote-access-tool+1
2191 month ago
CVE-2026-9198 preview

CVE-2026-9198

GitHub0xgh057r3c0n/cve-2026-9198

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

authenticationcommand-and-controlexploitation+4
11 month ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubdynamo2k1/cve-2026-33017

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

command-and-controlexploitationpayload-generation+4
1 month ago
wp2shell preview

wp2shell

GitHubmcipekci/wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

command-and-controlexploitationpayload-development+7
151 month ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubmverschu/cve-2026-63030

PoC Exploit of WordPress Core Unauthenticated RCE known as WP2Shell

command-and-controlexploitationpayload-generation+3
41 month ago
CVE-2023-26039 preview

CVE-2023-26039

GitHubungabunga-ctf/cve-2023-26039

Python exploit script for ZoneMinder OS Command Injection (CVE-2023-26039) enabling authenticated remote code execution and reverse shell via the API…

command-and-controlexploitationpayload-generation+3
1 month ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
91 month ago
Livepyre preview

Livepyre

GitHubsynacktiv/livepyre

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.

command-and-controlexploitationpayload-generation+3
1481 month ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Graphical RCE exploit tool for CVE-2025-55182 in Next.js RSC. Supports remote command execution, arbitrary JS execution, file read/write, directory…

command-and-controlexploitationpayload-generation+5
51 month ago
Previous12…27Next