Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
React2P4IM0Nshell preview

React2P4IM0Nshell

GitHubmammaninelsond/react2p4im0nshell

💥Extension Tool para Auditoría y Explotación avanzada RCE/Source Leak/Dos (CVE-2025-55182/83/84) para entornos Next.js y React Server Components…

educationexploit-frameworksinformation-gathering+6
3
8 months ago
CVE-2025-5548-Exploit-Development preview

CVE-2025-5548-Exploit-Development

GitHubgrospomg/cve-2025-5548-exploit-development

Practical lab focused on vulnerability analysis and exploit development, using FreeFloat FTP Server 1.0 as an educational buffer overflow case study…

binary-exploitationeducationexploit-frameworks+3
5 months ago
CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit preview

CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit

GitHubsimoesctt/ctt-proxylogon-rce-v1.0---convergent-time-theory-enhanced-microsoft-exchange-exploit

An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving…

command-and-controldata-exfiltrationexploitation+9
6 months ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
8 months ago
ms08-067 preview

ms08-067

GitHubbinracer/ms08-067

This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic…

exploitationexploit-frameworkspayload-development+4
9 months ago
CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065 preview

CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065

GitHubsimoesctt/ctt-exchange-rce-v1.0---microsoft-exchange-exploit-cvss-10.0-critical-cve-2021-26855-cve-2021-27065

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

command-and-controlexploitationexploit-frameworks+7
16 months ago
Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-42013 preview

Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-42013

GitHubvanshuk-bhagat/apache-http-server-vulnerabilities-cve-2021-41773-and-cve-2021-42013

In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and…

ctfeducationexploit-frameworks+4
1 year ago
CVE-2015-8522.RCE preview
Archived

CVE-2015-8522.RCE

GitHubdamariion/cve-2015-8522.rce

Tivoli FastBack Server (6.1.4) is vulnerable to a stack-based buffer overflow allowing threat-actors to gain Arbitrary Code Execution (ACE) via a…

binary-exploitationexploitationexploit-frameworks+8
4 months ago
msf-remote-console preview
Archived

msf-remote-console

GitHubqubasa/msf-remote-console

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

command-and-controlexploit-frameworkspayload-development+3
577 years ago
nate158g-m-w-n-l-p-d-a-o-e preview

nate158g-m-w-n-l-p-d-a-o-e

GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

exploit-frameworkspayload-generationpenetration-testing-frameworks+3
124 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubdevianntsec/cve-2025-55182

Advanced security research on CVE-2025-55182 (React2Shell). Features an exploitation framework with 6 functional impact scenarios (RCE to Secret…

educationexploitationexploit-frameworks+8
14 months ago
APOLOGEE preview
Archived

APOLOGEE

GitHubrosesecurity/apologee

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

authenticationexploitationexploit-frameworks+8
501 year ago
DanderSpritz_lab preview

DanderSpritz_lab

GitHubfrancisck/danderspritz_lab

A fully functional DanderSpritz lab in 2 commands

educationexploit-frameworkslabs-practice+5
4507 years ago
JNDI-Injection-Exploit-Plus preview

JNDI-Injection-Exploit-Plus

GitHubcckuailong/jndi-injection-exploit-plus

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…

exploit-frameworkspayload-developmentpenetration-testing+2
8822 years ago
Exploits preview

Exploits

GitHub1n3/exploits

Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity

ctfexploitationexploit-frameworks+3
2074 years ago
pentest_teamcity preview

pentest_teamcity

GitHubkacperszurek/pentest_teamcity

Pentest TeamCity using Metasploit

exploit-frameworkspayload-generationpenetration-testing+3
458 years ago
CVE-2022-41040-metasploit-ProxyNotShell preview

CVE-2022-41040-metasploit-ProxyNotShell

GitHubtaroballzchen/cve-2022-41040-metasploit-proxynotshell

the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated…

exploitationexploit-frameworkspenetration-testing+3
353 years ago
Neo preview

Neo

GitHubstillbigjosh/neo

The NeoC2 Framework

command-and-controlexploit-frameworksids-ips-evasion+8
351 month ago
Previous123Next