Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
108 results
Evil-Droid preview

Evil-Droid

GitHubm4sc3r4n0/evil-droid

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

android-securityeducationexploit-frameworks+4
1.1k
8 years ago
Anti-Virus-Evading-Payloads preview

Anti-Virus-Evading-Payloads

GitHubrosesecurity/anti-virus-evading-payloads

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

adversarial-attackeducationexploitation+4
74911 days ago
TheFatRat preview

TheFatRat

GitHubscreetsec/thefatrat

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

educationexploit-frameworksmalware-analysis+4
11.5k4 years ago
CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC preview

CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC

GitHubduc-nt/cve-2022-44268-imagemagick-arbitrary-file-read-poc

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

educationexploitationpayload-generation+3
2753 years ago
CVE-2023-3824 preview

CVE-2023-3824

GitHubjhonnybonny/cve-2023-3824

Vulnerability in PHP Phar files, due to buffer overflow, arises from insufficient length checks on file names within the Phar archive. Malicious…

binary-exploitationeducationexploitation+2
32 years ago
CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit- preview

CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

GitHubsxyrxyy/cve-2025-8088-winrar-proof-of-concept-poc-exploit-

CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

binary-exploitationeducationexploitation+3
731 year ago
ICT287-CVE-2022-42889 preview

ICT287-CVE-2022-42889

GitHubkosmicowl045/ict287-cve-2022-42889

Setup and exploit recreation for CVE-2022-42889 Text4Shell.

educationexploitationlabs-practice+3
5 months ago
xwiki-15.10.8-reverse-shell-cve-2025-24893 preview

xwiki-15.10.8-reverse-shell-cve-2025-24893

GitHubbishben/xwiki-15.10.8-reverse-shell-cve-2025-24893

CVE-2025-24893 RCE exploit for XWiki with reverse shell capability

exploitationpayload-generationpenetration-testing+3
1 year ago
turing-machine preview

turing-machine

GitHubintrinsic-propensity/turing-machine

Python implementation of Minsky's Universal Turing Machine with a built-in exploit demonstrating arbitrary code execution (CVE-2021-32471) for…

binary-exploitationeducationexploitation+4
794 years ago
heyserial preview
Archived

heyserial

GitHubmandiant/heyserial

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

curated-resourceseducationexploitation+6
1423 years ago
CVE-2021-44228_PoC preview

CVE-2021-44228_PoC

GitHubab0x90/cve-2021-44228_poc

Python proof-of-concept for CVE-2021-44228 (Log4Shell) that automates exploitation via a crafted Java payload, with argparse options for customizable…

educationexploitationpayload-generation+3
164 years ago
CVE-2024-29375 preview

CVE-2024-29375

GitHubismailcemunver/cve-2024-29375

Proof-of-concept for CSV injection in Addactis IBNRS 3.10.3.107, demonstrating Excel formula injection leading to OS command execution via crafted…

educationexploitationpayload-generation+2
2 years ago
lazylist-cve-poc preview

lazylist-cve-poc

GitHubyarocher/lazylist-cve-poc

POC for the CVE-2022-36944 vulnerability exploit

binary-exploitationeducationexploitation+2
113 years ago
CVE-2024-46451 preview

CVE-2024-46451

GitHubvidura2/cve-2024-46451

Python exploit for TOTOLINK AC1200 T8 buffer overflow vulnerability (CVE-2024-46451) with customizable payload generation and response logging for…

binary-exploitationeducationembedded-systems-security+3
21 year ago
CVE-2015-1578 preview

CVE-2015-1578

GitHubzeppperoni/cve-2015-1578

Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.

binary-exploitationeducationexploitation+5
3 years ago
CVE-2026-64638-POC preview

CVE-2026-64638-POC

GitHubimbas007/cve-2026-64638-poc

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

exploitationinformation-gatheringpayload-generation+4
91 month ago
exploit-CVE-2020-5844 preview

exploit-CVE-2020-5844

GitHubunicordev/exploit-cve-2020-5844

Exploit for CVE-2020-5844 (Pandora FMS v7.0NG.742) - Remote Code Execution

exploitationpayload-generationpenetration-testing+3
72 years ago
IntelTXE-PoC preview
Archived

IntelTXE-PoC

GitHubptresearch/inteltxe-poc

Intel Management Engine JTAG Proof of Concept

binary-exploitationdebuggersembedded-systems-security+6
5486 years ago
Previous123456Next