Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
256 results
CVE-2022-22947 preview

CVE-2022-22947

GitHubvancomycin-g/cve-2022-22947

Exploit tool for CVE-2022-22947 in Spring Cloud Gateway, featuring vulnerability detection, reverse shell, and outbound connectivity testing.

command-and-controlexploitationpayload-development+3
2
4 years ago
CVE-2025-55182-Toolbox preview

CVE-2025-55182-Toolbox

GitHublamaper/cve-2025-55182-toolbox

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

command-and-controlctfexploitation+6
18 months ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9833 months ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubcyglegit/cve-2025-24813

Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

exploitationpayload-developmentpenetration-testing+3
11 year ago
Nim-Reverse-Shell preview

Nim-Reverse-Shell

GitHubsn1r/nim-reverse-shell

A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell…

educationpayload-developmentpayload-generation+1
1243 years ago
CVE-2026-3228 preview

CVE-2026-3228

GitHubnull200ok/cve-2026-3228

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

exploitationpayload-developmentpenetration-testing+3
25 months ago
Lime-RAT preview
Archived

Lime-RAT

GitHubnyan-x-cat/lime-rat

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

command-and-controlcryptographydata-exfiltration+7
1.1k7 years ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
3.9k3 months ago
USBArmyKnife preview

USBArmyKnife

GitHubi-am-shodan/usbarmyknife

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

bluetooth-securitydata-exfiltrationhardware-hacking+8
2.9k2 months ago
SigFlip preview

SigFlip

GitHubmed0x2e/sigflip

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

binary-analysiscode-analysisdefensive-tools+5
1.3k3 years ago
Kautilya preview

Kautilya

GitHubsamratashok/kautilya

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

command-and-controldata-exfiltrationhardware-iot-security+6
8719 years ago
NyxInvoke preview

NyxInvoke

GitHubblacksnufkin/nyxinvoke

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

command-and-controlexploitationids-ips-evasion+6
2421 year ago
cromos preview

cromos

GitHubjimywork/cromos

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

command-and-controldata-exfiltrationlateral-movement+5
1248 years ago
shellex preview

shellex

GitHubtherealdreg/shellex

C-shellcode to hex converter, handy tool for paste & execute shellcodes in IDA PRO, gdb, windbg, radare2, ollydbg, x64dbg, immunity debugger & 010…

binary-analysisdebuggersexploitation+5
1133 years ago
CVE-2024-31317-PoC-Deployer preview

CVE-2024-31317-PoC-Deployer

GitHubwebldix/cve-2024-31317-poc-deployer

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

android-securitybinary-exploitationexploitation+5
531 year ago
java-remote-class-loader preview

java-remote-class-loader

GitHubjoaovarelas/java-remote-class-loader

Client-server tool for remotely loading and executing Java bytecode via ClassLoader and Reflect API, with ChaCha20 encryption and keepalive…

command-and-controlencryption-decryption-toolsexploitation+3
344 years ago
nimcrypt preview

nimcrypt

GitHubchaelsoo/nimcrypt

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

anti-botcommand-and-controlencryption-decryption-tools+6
281 month ago
OFBiz-Attack preview

OFBiz-Attack

GitHubd0g3-8bit/ofbiz-attack

A Tool For CVE-2023-49070/CVE-2023-51467 Attack

command-and-controlexploitationpayload-development+3
182 years ago
Previous12…15Next