Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
metasploit-ldapnightmare preview

metasploit-ldapnightmare

GitHub0xmetr0/metasploit-ldapnightmare

SafeBreaches CVE-2024-49113 POC(LdapNightmare) Integrated into Metasploit

exploitationexploit-frameworkspayload-development+2
1 year ago
LDAPFragger preview

LDAPFragger

GitHubfox-it/ldapfragger

C2 tool routing Cobalt Strike beacon data over LDAP user attributes for stealthy command-and-control in segmented networks.

command-and-controlexploit-frameworkspayload-development+2
1966 years ago
Log4Shell-CVE-2021-44228-PoC preview

Log4Shell-CVE-2021-44228-PoC

GitHubpierpaolosestito-dev/log4shell-cve-2021-44228-poc

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

command-and-controlexploitationpayload-development+3
13 years ago
Log4j_CVE-2021-44228 preview

Log4j_CVE-2021-44228

GitHubmuhammad-ali007/log4j_cve-2021-44228

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

command-and-controleducationexploitation+6
3 years ago
CVE-2021-44228-Log4Shell-POC preview

CVE-2021-44228-Log4Shell-POC

GitHubcoldfusionx/cve-2021-44228-log4shell-poc

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating JNDI-based remote code execution via LDAP and HTTP servers.

exploitationpayload-developmentpenetration-testing+2
24 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubdbgee/cve-2021-44228

Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.

exploitationpayload-developmentremote-access-tool+2
4 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubmaximofernandezriera/cve-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

exploitationpayload-developmentpenetration-testing+2
54 years ago
rogue-jndi preview

rogue-jndi

GitHubveracode-research/rogue-jndi

A malicious LDAP server for JNDI injection attacks

ctfeducationexploitation+4
1.1k2 years ago
JNDI-Injection-Exploit-Plus preview

JNDI-Injection-Exploit-Plus

GitHubcckuailong/jndi-injection-exploit-plus

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…

exploit-frameworkspayload-developmentpenetration-testing+2
8802 years ago
CVE-2022-44666 preview

CVE-2022-44666

GitHubj00sean/cve-2022-44666

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

exploitationpayload-developmentphishing-tools+2
1543 years ago
CVE-2024-49112-PoC preview

CVE-2024-49112-PoC

GitHubbo0l3an/cve-2024-49112-poc

CVE-2024-49112 LDAP RCE PoC and Metasploit Module

exploitationexploit-frameworkspayload-development+3
121 year ago
log4j-cve-2021-44228 preview

log4j-cve-2021-44228

GitHubmanuel-alvarez-alvarez/log4j-cve-2021-44228

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

educationexploitationpayload-development+3
54 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubracoon-rac/cve-2021-44228

Step-by-step reproduction guide for CVE-2021-44228 (Log4Shell) with JDK 8u20, vulnerable Log4j 2.14.1, marshalsec LDAP server, and custom payload…

educationexploitationlabs-practice+3
3 years ago
cve-2021-44228-helpers preview

cve-2021-44228-helpers

GitHubuint0/cve-2021-44228-helpers

Helpers, vulnerable applications, and exploit examples for CVE-2021-44228 (Log4Shell). Includes LDAP exfiltration server, RMI deserialization…

educationexploitationlabs-practice+3
4 years ago
cve-2021-44228-log4j-test preview

cve-2021-44228-log4j-test

GitHubbumheehan/cve-2021-44228-log4j-test

Demonstrates Log4Shell (CVE-2021-44228) exploitation with LDAP server, malicious JNDI payload, and vulnerable Spring Boot application for security…

educationexploitationmalware-analysis+3
4 years ago
CVE-2024-49112 preview

CVE-2024-49112

GitHubccievoice2009/cve-2024-49112

Exploit for CVE-2024-49112, a critical Windows LDAP RCE vulnerability, triggering a crash via crafted Netlogon and LDAP interactions.

exploitationexploit-frameworkspayload-development+3
31 year ago
log4shell preview

log4shell

GitHubjxerome/log4shell

Educational demonstration of the Log4Shell vulnerability (CVE-2021-44228) with JNDI LDAP payloads for experimental testing on your own systems.

educationexploitationlabs-practice+3
4 years ago
Log4Shell-Payloads preview

Log4Shell-Payloads

GitHubifconfig-me/log4shell-payloads

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

curated-resourceseducationexploitation+4
81 year ago
Previous12Next