Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
K8tools preview

K8tools

GitHubk8gege/k8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

command-and-controlexploit-frameworkslateral-movement+9
6.2k
1 year ago
CVE-2022-26134-Godzilla-MEMSHELL preview

CVE-2022-26134-Godzilla-MEMSHELL

GitHubbeichendream/cve-2022-26134-godzilla-memshell

Java-based exploit for CVE-2022-26134 that injects a Godzilla webshell into Confluence servers, enabling remote code execution with password and key…

command-and-controlexploitationpayload-generation+3
3404 years ago
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

binary-analysiscommand-and-controlembedded-systems-security+7
21 year ago
poisontap preview

poisontap

GitHubsamyk/poisontap

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

authenticationcommand-and-controldata-exfiltration+7
6.5k7 years ago
dnscat2 preview

dnscat2

GitHubiagox86/dnscat2

Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

command-and-controldata-exfiltrationdns-analysis+5
4.0k4 years ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubjumbo-wjb/cve-2020-0688

CVE-2020-0688 - Exchange

command-and-controlexploitationpenetration-testing+2
666 years ago
CVE-2018-2380 preview

CVE-2018-2380

GitHuberpscanteam/cve-2018-2380

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

command-and-controlexploitationpayload-generation+3
518 years ago
ddoor preview

ddoor

GitHubrek7/ddoor

DDoor - cross platform backdoor using dns txt records

anti-botcommand-and-controldns-analysis+5
304 years ago
CVE-2019-15107-EXPLOIT preview

CVE-2019-15107-EXPLOIT

GitHubk3ystr0k3r/cve-2019-15107-exploit

A PoC exploit for CVE-2019-15107 - Webmin Remote Code Execution

command-and-controleducationexploitation+3
102 years ago
CVE-2025-47227_CVE-2025-47228 preview

CVE-2025-47227_CVE-2025-47228

GitHubsynacktiv/cve-2025-47227_cve-2025-47228

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

authentication-authorizationcommand-and-controlexploitation+3
111 year ago
WebminRCE-EXP-CVE-2019-15107- preview

WebminRCE-EXP-CVE-2019-15107-

GitHubalewong/webminrce-exp-cve-2019-15107-

Remote Code Execution Vulnerability in Webmin

command-and-controlexploitationpayload-generation+3
36 years ago
CVE-2025-63406-PoC preview

CVE-2025-63406-PoC

GitHubnxvh1337/cve-2025-63406-poc

Small PoC to automate exploitation of CVE-2025-63406.

command-and-controlexploitationpenetration-testing+2
49 months ago
PRTG-Network-Monitor-18.2.38---Authenticated-Remote-Code-Execution-CVE-2018-9276 preview

PRTG-Network-Monitor-18.2.38---Authenticated-Remote-Code-Execution-CVE-2018-9276

GitHubac8999/prtg-network-monitor-18.2.38---authenticated-remote-code-execution-cve-2018-9276

Python Exploit for CVE: 2018-9276

command-and-controlexploitationpayload-generation+3
4 months ago
CVE-2019-15107-Webmin-RCE-PoC preview

CVE-2019-15107-Webmin-RCE-PoC

GitHubmattb709/cve-2019-15107-webmin-rce-poc

A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.

command-and-controleducationexploitation+3
11 year ago
CVE-2019-9193-Postgresql-RCE preview

CVE-2019-9193-Postgresql-RCE

GitHubcybersrmutl/cve-2019-9193-postgresql-rce

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

command-and-controldatabase-securityexploitation+2
7 months ago
CVE-2024-23346 preview

CVE-2024-23346

GitHubmawk0235/cve-2024-23346

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

command-and-controlexploitationpenetration-testing+2
1 year ago
odat preview

odat

GitHubquentinhardy/odat

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

command-and-controldatabase-securityexploitation+4
1.8k5 months ago
IIS-Raid preview

IIS-Raid

GitHub0x09al/iis-raid

A native backdoor module for Microsoft IIS (Internet Information Services)

command-and-controlpassword-crackingpersistence-mechanisms+1
5536 years ago
Previous12Next