Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
Decepticon preview

Decepticon

GitHubpurpleailab/decepticon

Autonomous Hacking Agent for Red Team

ai-securitycommand-and-controlctf+9
5.6k3 days ago
cve-2022-36804 preview

cve-2022-36804

GitHubwalnutsecurity/cve-2022-36804

A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability…

command-and-controlexploitationlabs-practice+3
83 years ago
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
21 month ago
CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept preview

CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

GitHubkra1t0/cve-2025-33053-webdav-rce-poc-and-c2-concept

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

command-and-controleducationexploitation+5
31 year ago
TTPRunner preview

TTPRunner

GitHubantonlovesdnb/ttprunner

Run TTPs, with AI!

command-and-controleducationexploit-frameworks+7
1427 months ago
EasyTokens preview

EasyTokens

GitHubsecdev02/easytokens

Kali365 - EvilTokens Replica

adversarial-attackauthenticationcloud-security+7
722 months ago
composer-CVE-2026-40261-CVE-2026-40176-PoC preview

composer-CVE-2026-40261-CVE-2026-40176-PoC

GitHubterminat0r7031/composer-cve-2026-40261-cve-2026-40176-poc

Proof-of-concept demonstrating command injection vulnerabilities in Composer's Perforce driver, with two attack vectors and Docker-based testing.

command-and-controleducationexploitation+2
25 months ago
CVE-2026-39987 preview

CVE-2026-39987

GitHub0xblackash/cve-2026-39987

CVE-2026-39987

command-and-controleducationexploitation+5
5 months ago
CVE-2026-42945-POC preview

CVE-2026-42945-POC

GitHubcipherspy/cve-2026-42945-poc

exploit for CVE-2026-42945

binary-exploitationcommand-and-controlctf+7
644 months ago
CVE-2024-49368 preview

CVE-2024-49368

GitHubaashay221999/cve-2024-49368

Explorations of CVE-2024-49368 + Exploit Development

command-and-controleducationexploitation+3
1 year ago
spring-boot-log4j-cve-2021-44228-docker-lab preview

spring-boot-log4j-cve-2021-44228-docker-lab

GitHubtwseptian/spring-boot-log4j-cve-2021-44228-docker-lab

Spring Boot Log4j - CVE-2021-44228 Docker Lab

command-and-controleducationexploitation+4
274 years ago
cve-2022-33891 preview

cve-2022-33891

GitHubakbartrilaksana/cve-2022-33891

Python proof-of-concept for Apache Spark Shell Command Injection (CVE-2022-33891), featuring sleep-based detection, interactive command execution,…

command-and-controlexploitationpayload-generation+3
38 months ago
cve-2022-33891 preview
Archived

cve-2022-33891

GitHubhuskyhacks/cve-2022-33891

Apache Spark Shell Command Injection Vulnerability

command-and-controlexploitationpayload-generation+3
884 years ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
6796 days ago
rustbof preview

rustbof

GitHubjoaoviictorti/rustbof

A Rust template for writing Beacon Object Files (BOFs)

command-and-controlpayload-developmentpost-exploitation+1
1337 months ago
CVE-2026-27626-PoC preview

CVE-2026-27626-PoC

GitHub0xh7ml/cve-2026-27626-poc

OliveTin is a self-hosted web UI for exposing predefined shell commands to end users. This repository contains a proof-of-concept demonstrating two…

command-and-controlexploitationpayload-development+4
12 months ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
9 months ago
Covenant preview

Covenant

GitHubcobbr/covenant

Covenant is a collaborative .NET C2 framework for red teamers.

command-and-controlexploit-frameworkspayload-generation+2
4.7k5 years ago
Previous12345Next