Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
BounceBack preview

BounceBack

GitHubd00movenok/bounceback

↕️🤫 Stealth redirector for your red team operation security

command-and-controlids-ips-evasionpenetration-testing+3
1.1k2 months ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k3 months ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubluoqichen/cve-2025-55182-poc

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

command-and-controlexploitationpayload-development+5
6 months ago
fortinet-fortiweb-cve-2025-64446-58034 preview

fortinet-fortiweb-cve-2025-64446-58034

GitHublequoca/fortinet-fortiweb-cve-2025-64446-58034

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

authentication-authorizationcommand-and-controlexploitation+3
9 months ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
9 months ago
CVE-2025-55182-NextJS-Scanner-React2Shell-PoC preview

CVE-2025-55182-NextJS-Scanner-React2Shell-PoC

GitHubexrienz/cve-2025-55182-nextjs-scanner-react2shell-poc

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

command-and-controlexploitationpayload-generation+5
9 months ago
react2shell-ultimate preview

react2shell-ultimate

GitHubhackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

command-and-controlexploitationpayload-generation+4
1559 months ago
CVE-2025-55182-PoC preview

CVE-2025-55182-PoC

GitHubummitkin/cve-2025-55182-poc

react2shell PoC with Go / CVE-2025-55182

command-and-controlexploitationpayload-generation+3
19 months ago
r2s preview

r2s

GitHubzamdevio/r2s

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

command-and-controlexploitationinformation-gathering+5
29 months ago
modsecurity-backdoor preview

modsecurity-backdoor

GitHubazurit/modsecurity-backdoor

This is a proof-of-concept of malicious software running inside of ModSecurity WAF.

command-and-controlids-ips-evasionpost-exploitation+3
341 year ago
bantam preview

bantam

GitHubgellin/bantam

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

command-and-controlencryption-decryption-toolsids-ips-evasion+5
2824 years ago
JNDI-Exploit-1.2-log4shell preview

JNDI-Exploit-1.2-log4shell

GitHub34zy/jndi-exploit-1.2-log4shell

Details : CVE-2021-44228

command-and-controlexploitationpayload-generation+3
4 years ago