Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
KittyStager preview

KittyStager

GitHubenelg52/kittystager

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

command-and-controleducationencryption-decryption-tools+6
228
3 years ago
CVE-2021-36260-hikvision preview

CVE-2021-36260-hikvision

GitHubshubtheone/cve-2021-36260-hikvision

Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command…

command-and-controlexploitationiot-security+3
8 months ago
IIS-Backdoor preview

IIS-Backdoor

GitHubnu11secur1ty/iis-backdoor

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

command-and-controlexploitationids-ips-evasion+4
346 years ago
CVE-2024-27348 preview

CVE-2024-27348

GitHubzeyad-azima/cve-2024-27348

Apache HugeGraph Server RCE Scanner ( CVE-2024-27348 )

command-and-controlexploitationpenetration-testing+3
602 years ago
SnitchDNS preview

SnitchDNS

GitHubctxis/snitchdns

Database Driven DNS Server with a Web UI

command-and-controldata-exfiltrationdns-analysis+7
2442 years ago
React2Shell preview

React2Shell

GitHubprowlsec/react2shell

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

command-and-controlexploitationpayload-generation+4
19 months ago
melting-cobalt preview
Archived

melting-cobalt

GitHubsplunk/melting-cobalt

A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object

command-and-controlinformation-gatheringnetwork-security+3
1693 years ago
CVE-2025-47812 preview

CVE-2025-47812

GitHub0xjuarez/cve-2025-47812

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…

command-and-controlexploitationpenetration-testing+3
16 months ago
rschunter preview

rschunter

GitHubsumanrox/rschunter

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

command-and-controlexploitationpenetration-testing+3
379 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubatastycookie/cve-2025-55182

Python CLI exploit and scanner for CVE-2025-55182, a critical RCE in React Server Components, with command execution and nuclei-based detection.

command-and-controleducationexploitation+3
9 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xsj/cve-2025-55182

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

command-and-controlexploitationpenetration-testing+3
17 months ago
PAKURI-THON preview

PAKURI-THON

GitHub01rabbit/pakuri-thon

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

command-and-controlexploit-frameworksinformation-gathering+7
284 years ago
HTTP-Basma preview

HTTP-Basma

GitHubnetomize/http-basma

In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and…

command-and-controlinformation-gatheringmalware-analysis+6
1 month ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubjenderal92/cve-2026-41940

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

authenticationcommand-and-controlexploitation+6
43 months ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubeynaexp/cve-2025-55182-poc

Poc for CVE-2025-55182 (remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including…

command-and-controleducationexploitation+3
69 months ago
POC-CVE-2025-55182 preview

POC-CVE-2025-55182

GitHubdevvaibhav07/poc-cve-2025-55182

POC-CVE-2025-55182

command-and-controlexploitationpayload-generation+3
9 months ago
CVE-2023-38646 preview

CVE-2023-38646

GitHubkh4sh3i/cve-2023-38646

Python exploit for Metabase pre-authentication remote code execution (CVE-2023-38646) with setup-token extraction and collaborator callback for…

command-and-controlexploitationpenetration-testing+3
93 years ago
cve-2025-66398 preview

cve-2025-66398

GitHubjoshuavanderpoll/cve-2025-66398

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

command-and-controleducationexploitation+7
36 months ago
Previous123Next