Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.4k
16 days ago
AllAboutBugBounty preview

AllAboutBugBounty

GitHubdaffainfo/allaboutbugbounty

All about bug bounty (bypasses, payloads, and etc)

ctfcurated-resourceseducation+7
6.8k3 years ago
AwesomeXSS preview

AwesomeXSS

GitHubs0md3v/awesomexss

Awesome XSS stuff

ctfcurated-resourceseducation+6
5.1k1 year ago
reverse-shell-generator preview

reverse-shell-generator

GitHub0dayctf/reverse-shell-generator

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

ctfexploitationpayload-development+6
4.0k4 months ago
penelope preview

penelope

GitHubbrightio/penelope

Penelope Shell Handler

command-and-controlctfpayload-generation+5
2.0k2 days ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k2 months ago
xeca preview

xeca

GitHubpostrequest/xeca

PowerShell payload generator

command-and-controlctfexploitation+6
1204 years ago
Hack-Tool preview

Hack-Tool

GitHubrevanmalang/hack-tool

ALL IN ONE Hacking Tool For Hackers

ctfexploit-frameworksforensics+9
503 years ago
Code-Roulette preview

Code-Roulette

GitHubsorcerio/code-roulette

Code Roulette is a terminal interface based (TUI), online multiplayer, Russian Roulette game where the loser executes the winner's Python payload…

command-and-controlctfeducation+3
76 months ago
CVE-2024-23346-exploit preview

CVE-2024-23346-exploit

GitHubdavidaroca27/cve-2024-23346-exploit

This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious…

ctfexploitationpayload-generation+3
41 year ago
CVE-2023-33733-Exploit-PoC preview

CVE-2023-33733-Exploit-PoC

GitHubl41kaa/cve-2023-33733-exploit-poc

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

ctfexploitationpayload-generation+3
32 years ago
CVE-2025-4138_tarfile_filter_bypass preview

CVE-2025-4138_tarfile_filter_bypass

GitHubthefizzyfish/cve-2025-4138_tarfile_filter_bypass

CVE-2025-4138 - Python Arbitrary file write outside extraction directory

ctfexploitationpayload-generation+3
36 months ago
jwt-key-confusion-poc preview

jwt-key-confusion-poc

GitHubaalex954/jwt-key-confusion-poc

JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction

ctfexploitationpayload-generation+3
24 years ago
Variatype.htb-CVE-2025-66034 preview

Variatype.htb-CVE-2025-66034

GitHubliquid1998/variatype.htb-cve-2025-66034

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

ctfexploitationpayload-generation+3
25 months ago
CVE-2024-28397-Exploit-Automation preview

CVE-2024-28397-Exploit-Automation

GitHubl1337xi/cve-2024-28397-exploit-automation

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

ctfeducationexploitation+3
28 months ago
CVE-2025-66034-htb-ctf preview

CVE-2025-66034-htb-ctf

GitHubjwsly12/cve-2025-66034-htb-ctf

Exploit for VariaType HTB machine leveraging XML injection in fontTools to achieve RCE via PHP reverse shell payload in .designspace metadata.

ctfeducationexploitation+3
14 months ago
CVE-2023-4220-Proof-of-concept preview

CVE-2023-4220-Proof-of-concept

GitHublgenagul/cve-2023-4220-proof-of-concept

Chamilo LMS Unauthenticated Big Upload File that allows remote code execution

ctfexploitationpayload-generation+3
2 years ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubhklabcr/cve-2011-2523

Manual and automated exploitation walkthrough for vsftpd 2.3.4 backdoor (CVE-2011-2523) with custom reverse shell payload and Metasploit integration…

ctfeducationexploitation+5
1 year ago
Previous12Next