Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
payloads preview

payloads

GitHubfoospidy/payloads

Git All the Payloads! A collection of web attack payloads.

ctfcurated-resourceseducation+6
4.0k5 years ago
MalQR.github.io preview

MalQR.github.io

GitHubmalqr/malqr.github.io

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

fuzzingpayload-generationpenetration-testing+1
1274 years ago
rcekit preview

rcekit

GitHubkabiri-labs/rcekit

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

command-and-controlexploitationfuzzing+8
258 days ago
haptyc preview

haptyc

GitHubdefparam/haptyc

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

fuzzingpayload-generationpenetration-testing+1
935 years ago
ZIPFileRaider preview

ZIPFileRaider

GitHubdestine21/zipfileraider

ZIP File Raider - Burp Extension for ZIP File Payload Testing

fuzzingpayload-generationpenetration-testing+2
716 years ago
cve-2025-9951-ffmpeg-jp2-poc preview

cve-2025-9951-ffmpeg-jp2-poc

GitHubfm0ss/cve-2025-9951-ffmpeg-jp2-poc

Proof-of-concept for CVE-2025-9951 demonstrating controlled callback execution in FFmpeg via JPEG 2000 component-mapping mismatch. Includes write-up,…

binary-exploitationexploitationfuzzing+3
2 months ago
pFuzz preview

pFuzz

GitHubredsection/pfuzz

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

fuzzingpenetration-testingred-teaming+2
1615 years ago
firefly preview

firefly

GitHubbrum3ns/firefly

High-performance black-box fuzzer for web applications with built-in payload engine, request verification, tampering, encoding, and advanced…

fuzzingpenetration-testingvulnerability-scanners+1
4402 years ago
Payload-and-Polyglot-Lists preview

Payload-and-Polyglot-Lists

GitHubgromhacks/payload-and-polyglot-lists

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

educationfuzzingosint+4
386 months ago
CVE-2019-2107 preview

CVE-2019-2107

GitHubinfiniteloopers/cve-2019-2107

Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

android-securitybinary-exploitationexploitation+4
47 years ago
PixelSmash preview

PixelSmash

GitHubse1ims/pixelsmash

Proof-of-concept and lab harness for CVE-2026-8461, an out-of-bounds write in FFmpeg's MagicYUV decoder, with payload generator and Qt demo player.

binary-exploitationeducationexploitation+6
15 days ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubfkshield/cve-2025-5548

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

binary-exploitationdynamic-analysis-sandboxingeducation+9
3 months ago
CVE-2025-46817-PoC preview

CVE-2025-46817-PoC

GitHubslayerkkkk/cve-2025-46817-poc

C-based exploit for CVE-2025-46817, a Redis integer overflow vulnerability, enabling crash detection and potential RCE via Lua unpack() payload.

database-securityexploitationfuzzing+2
211 months ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubpopclom/cve-2025-5548

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

binary-exploitationdebuggerseducation+8
6 months ago
CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC preview

CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC

GitHubabrewer251/cve-2024-38475_sonicboom_apache_url_traversal_poc

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

exploitationfuzzingpenetration-testing+3
1 year ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerdynamic-code-analysisfuzzing+8
15.2k1 year ago
eero-zero-length-ipv6-options-header-dos preview

eero-zero-length-ipv6-options-header-dos

GitHubnomis/eero-zero-length-ipv6-options-header-dos

eeroOS Ethernet Interface Denial of Service Vulnerability (CVE-2023-5324)

exploitationfuzzinghardware-iot-security+3
13 years ago
CVE-2011-0762 preview

CVE-2011-0762

GitHubs3mpr1linux/cve-2011-0762

Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db

exploitationfuzzingpenetration-testing+2
1 year ago
Previous12Next