Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
295 results
PoC-RCE-CVE-2025-55182 preview

PoC-RCE-CVE-2025-55182

GitHubilixm/poc-rce-cve-2025-55182

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

command-and-controlexploitationinformation-gathering+7
9 months ago
Samba-Exploit-CVE-2007-2447 preview

Samba-Exploit-CVE-2007-2447

GitHubnulltrace1336/samba-exploit-cve-2007-2447

Step-by-step guide to exploiting Samba 3.0.20 (CVE-2007-2447) using Metasploit, including Nmap scanning, payload setup, and reverse shell execution.

command-and-controlexploitationexploit-frameworks+3
9 months ago
metasploitable2-exploitation-metasploit preview

metasploitable2-exploitation-metasploit

GitHubethicalhackinglabs/metasploitable2-exploitation-metasploit

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…

command-and-controldata-exfiltrationeducation+9
3 months ago
Apache-Struts preview

Apache-Struts

GitHubc002/apache-struts

Python-based exploit for Apache Struts CVE-2017-5638 with single URL and batch scanning modes, vulnerability checking, and Nmap reconnaissance…

command-and-controlexploitationpenetration-testing+3
9 years ago
HTTP-Basma preview

HTTP-Basma

GitHubnetomize/http-basma

In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and…

command-and-controlinformation-gatheringmalware-analysis+6
2 months ago
red-kube preview

red-kube

GitHublightspin-tech/red-kube

Red Team K8S Adversary Emulation Based on kubectl

adversarial-attackcloud-securitycommand-and-control+6
8275 years ago
sunlogin_rce preview

sunlogin_rce

GitHubmr-xn/sunlogin_rce

向日葵 RCE

command-and-controlexploitationpenetration-testing+3
5144 years ago
faraday-cli preview

faraday-cli

GitHubinfobyte/faraday-cli

Faraday's Command Line Interface

command-and-controldevsecopspenetration-testing+1
534 months ago
gopher47 preview

gopher47

GitHuban00brektn/gopher47

A third-party Gopher Assassin for the Havoc Framework.

command-and-controlpenetration-testingport-scanning+4
432 years ago
CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner preview

CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner

GitHubcyberdudebivash/cyberdudebivash-fortisiem-cve-2025-64155-scanner

Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and…

command-and-controlexploitationpenetration-testing+3
18 months ago
Evil-M5Project preview

Evil-M5Project

GitHub7h30th3r0n3/evil-m5project

Multi-purpose WiFi penetration testing toolkit for M5Stack devices. Performs network scanning, evil-twin attacks, deauthentication, captive portal…

bluetooth-securitycommand-and-controleducation+9
2.7k11 days ago
emp3r0r preview

emp3r0r

GitHubjm33-m0/emp3r0r

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

anti-botcommand-and-controlids-ips-evasion+10
1.8k0 days ago
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
265 months ago
CVE-2026-82222 preview

CVE-2026-82222

GitHubghostlyrootb2h/cve-2026-82222

Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

command-and-controlexploitationinformation-gathering+5
20 days ago
CVE-2026-14762-PoC-Exploit preview

CVE-2026-14762-PoC-Exploit

GitHubtc4dy/cve-2026-14762-poc-exploit

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

command-and-controldatabase-securityexploitation+7
22 months ago
abyss-c2 preview

abyss-c2

GitHubflags-alt/abyss-c2

Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning,…

command-and-controleducationexploit-frameworks+7
24 months ago
CVE-2024-49369 preview

CVE-2024-49369

GitHubquantum-sicarius/cve-2024-49369

Exploit tool for CVE-2024-49369 in Icinga, enabling subnet scanning, agent takeover via JSON-RPC impersonation, arbitrary command execution, and…

command-and-controlexploitationinformation-gathering+3
21 year ago
WP-Bricks-Exploit-CVE-2024-25600 preview

WP-Bricks-Exploit-CVE-2024-25600

GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

command-and-controlexploitationinformation-gathering+7
12 months ago
Previous12…17Next