Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
rosemary preview

rosemary

GitHubblue0x1/rosemary

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

command-and-controldns-analysislateral-movement+4
142 months ago
GPON preview

GPON

GitHubexiahan/gpon

Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor…

command-and-controlexploitationiot-security+3
8 years ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub0xbinder/cve-2021-4045

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

command-and-controlexploitationhardware-iot-security+3
92 years ago
CVE-2025-57174 preview

CVE-2025-57174

GitHubsemaja22/cve-2025-57174

CVE-2025-57174 Unauthenticated Remote Command Execution

command-and-controlexploitationiot-security+3
1 year ago
IIS-Raid preview

IIS-Raid

GitHub0x09al/iis-raid

A native backdoor module for Microsoft IIS (Internet Information Services)

command-and-controlpassword-crackingpersistence-mechanisms+1
5516 years ago
bepr preview

bepr

GitHubaperocky/bepr

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

authenticationcommand-and-controlpenetration-testing+3
4 months ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubklezvirus/cve-2021-40444

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

command-and-controleducationexploitation+4
8362 years ago
IIS-Backdoor preview

IIS-Backdoor

GitHubnu11secur1ty/iis-backdoor

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

command-and-controlexploitationids-ips-evasion+4
346 years ago
CVE-2018-15982 preview

CVE-2018-15982

GitHubscanfsec/cve-2018-15982

Aggressor Script to launch IE driveby for CVE-2018-15982.

command-and-controlexploitationpayload-generation+3
296 years ago
CVE-2023-20209 preview

CVE-2023-20209

GitHubpeter5he1by/cve-2023-20209

Detailed technical analysis and proof-of-concept exploit for CVE-2023-20209, a post-authentication remote code execution vulnerability in Cisco…

command-and-controlexploitationpenetration-testing+3
3 years ago
SirepRAT preview

SirepRAT

GitHubsafebreach-labs/sireprat

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

command-and-controlexploitationiot-security+4
3895 years ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubverylazytech/cve-2024-10914

POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS

command-and-controlexploitationiot-security+3
481 year ago
CVE-2024-53375 preview

CVE-2024-53375

GitHubthottysploity/cve-2024-53375

TP-Link Archer AXE75 Authenticated Command Injection

command-and-controlexploitationhardware-security+4
221 year ago
cve-2022-31898 preview

cve-2022-31898

GitHubgigaryte/cve-2022-31898

Proof-of-concept exploit for CVE-2022-31898, a command injection vulnerability in GL-iNet routers (firmware < 3.215). Provides reverse shell via…

command-and-controlexploitationiot-security+3
183 years ago
my-little-honeypot preview

my-little-honeypot

GitHubpandipanda69/my-little-honeypot

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

command-and-controliot-securitymalware-analysis+2
179 years ago
CVE-2022-39073 preview

CVE-2022-39073

GitHubv0lp3/cve-2022-39073

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

command-and-controlexploitationiot-security+3
113 years ago
CVE-2024-7120 preview

CVE-2024-7120

GitHubgh-ost00/cve-2024-7120

Proof-of-concept exploit for CVE-2024-7120 command injection vulnerability in RAISECOM gateway devices. Provides exploitation details, affected…

command-and-controlexploitationiot-security+3
82 years ago
Previous123Next