Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
StealC-Stealer-RuntimeBroker-Hollowing-C2-Extraction-Payload-Extraction-Analysis preview

StealC-Stealer-RuntimeBroker-Hollowing-C2-Extraction-Payload-Extraction-Analysis

GitHubkaandemir993/stealc-stealer-runtimebroker-hollowing-c2-extraction-payload-extraction-analysis

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

command-and-controldata-exfiltrationdigital-forensics+7
6h 33m ago
WeaveMark preview

WeaveMark

GitHubqkrrkd90-source/weavemark

Reference implementation of a multi-bit LLM watermarking scheme using coded payload spreading, unbiased reweighting, and soft-decision ECC decoding…

ai-securitycryptographyeducation+2
1 month ago
CVE-2026-12295-UXXS-in-my-wasm preview

CVE-2026-12295-UXXS-in-my-wasm

GitHubsneakynachos/cve-2026-12295-uxxs-in-my-wasm

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

exploitationpapers-researchpayload-development+2
120 days ago
CVE-2026-64633 preview

CVE-2026-64633

GitHubtfawnies/cve-2026-64633

Generated CVE-2026-64633 analysis payloads with treatment/control document variants and a manifest mapping IDs and pairs for reproducing the…

curated-resourcespapers-researchpayload-generation+1
1 month ago
marshalsec preview

marshalsec

GitHubmbechler/marshalsec

Java deserialization vulnerability exploitation tool with payload generators for multiple marshallers (Jackson, XStream, SnakeYAML) and JNDI…

educationexploitationpapers-research+5
3.7k1 year ago
samsung-q60t-exploit preview

samsung-q60t-exploit

GitHubsynacktiv/samsung-q60t-exploit

Exploit suite targeting Tizen-based Samsung Q60T TV, including v8 and kernel exploits, firmware decryption, and root shell access via payload…

binary-exploitationembedded-systems-securityexploitation+4
884 years ago
CVE-2025-56379 preview

CVE-2025-56379

GitHubmoalali/cve-2025-56379

A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or…

educationexploitationpapers-research+3
11 months ago
Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis preview

Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis

GitHubkaandemir993/salat-stealer-telegram-proxy-decoy-c2-analysis

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

binary-analysiscommand-and-controleducation+6
51 month ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubtrganda/cve-2021-22204

In-depth technical analysis of CVE-2021-22204 (ExifTool RCE) with PoC reproduction, payload construction, and Perl code review of the vulnerable DjVu…

binary-exploitationcode-analysiseducation+3
34 years ago
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection preview

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

GitHubhunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

Proof-of-concept exploit for CVE-2026-58116 demonstrating remote code execution in LLaMA-Factory WebUI via trust_remote_code model path injection.…

code-analysisctfeducation+5
2 months ago
CVE-2026-39200 preview

CVE-2026-39200

GitHubr00tali/cve-2026-39200

The value of the produk request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The…

educationpapers-researchpenetration-testing+3
1 month ago
CVE-2025-66478-Research-Proof-of-Concept preview

CVE-2025-66478-Research-Proof-of-Concept

GitHubnilfredb/cve-2025-66478-research-proof-of-concept

Proof-of-concept exploit for CVE-2025-66478 targeting unsafe React Server Components payload handling in Next.js. Includes automated payload…

educationexploitationpapers-research+3
3 months ago
CVE-2021-40444--CABless preview

CVE-2021-40444--CABless

GitHubedubr2020/cve-2021-40444--cabless

Modified code so that we don´t need to rely on CAB archives

educationexploitationpapers-research+2
1044 years ago
CVE-2018-12533 preview

CVE-2018-12533

GitHubllamaonsecurity/cve-2018-12533

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

exploitationlabs-practicepapers-research+3
95 years ago
AwesomeXSS preview

AwesomeXSS

GitHubs0md3v/awesomexss

Awesome XSS stuff

ctfcurated-resourceseducation+6
5.1k1 year ago
CVE-2024-48415 preview

CVE-2024-48415

GitHubkhaliquesx/cve-2024-48415

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

educationpapers-researchvulnerability-analysis+2
1 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubkavienanj/cve-2025-55182

Detailed technical walkthrough of CVE-2025-55182 (React2Shell), tracing React's Flight protocol internals to explain the exploit chain, payload…

educationexploitationpapers-research+3
389 months ago
React2ShellPoC preview

React2ShellPoC

GitHubgit0xlai/react2shellpoc

This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It…

educationexploitationpapers-research+3
8 months ago
Previous12Next