Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
67 results
Pokemon-Shellcode-Loader preview

Pokemon-Shellcode-Loader

GitHubtechryptic/pokemon-shellcode-loader

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

adversarial-attackpayload-developmentpayload-generation+3
128
4 years ago
IronSharpPack preview

IronSharpPack

GitHubbc-security/ironsharppack

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

ids-ips-evasionpayload-developmentpayload-generation+2
1212 years ago
potential-cassandra preview

potential-cassandra

GitHubcroway/potential-cassandra

CVE discovery

exploitationpayload-generationpenetration-testing+1
12 years ago
Automated-blind-xss-search-for-Burp-Suite preview

Automated-blind-xss-search-for-Burp-Suite

GitHubianxtianxt/automated-blind-xss-search-for-burp-suite

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

payload-generationpenetration-testingvulnerability-scanners+2
96 years ago
CVE-2026-58480 preview

CVE-2026-58480

GitHubshinthink/cve-2026-58480

CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

exploitationpayload-generationpenetration-testing+3
31 month ago
CVE-2025-10041 preview

CVE-2025-10041

GitHubnxploited/cve-2025-10041

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

exploitationids-ips-evasionpayload-generation+3
310 months ago
CVE-2026-3891 preview

CVE-2026-3891

GitHubnxploited/cve-2026-3891

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
65 months ago
PwnSTAR preview

PwnSTAR

GitHubsilverfoxx/pwnstar

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

captcha-bypassdns-analysisexploitation+7
2608 years ago
CVE-2023-3452-PoC preview

CVE-2023-3452-PoC

GitHubleoanggal1/cve-2023-3452-poc

Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)

exploitationpayload-generationpenetration-testing+3
172 years ago
CVE-2023-38646 preview

CVE-2023-38646

GitHubsecurezeron/cve-2023-38646

POC for CVE-2023-38646

exploitationpayload-generationpenetration-testing+3
203 years ago
CVE-2021-44228-Apache-Log4j-Rce preview

CVE-2021-44228-Apache-Log4j-Rce

GitHubtangxiaofeng7/cve-2021-44228-apache-log4j-rce

Apache Log4j 远程代码执行

educationexploitationpayload-generation+4
894 years ago
CVE-2021-44228-Apache-Log4j-Rce preview

CVE-2021-44228-Apache-Log4j-Rce

GitHubyuuki1967/cve-2021-44228-apache-log4j-rce

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection, LDAP reference server, and WAF bypass techniques for testing Log4j RCE…

exploitationpayload-generationpenetration-testing+3
8 months ago
Unauthenticated-CVE-2020-0796-PoC preview

Unauthenticated-CVE-2020-0796-PoC

GitHubmaxpl0it/unauthenticated-cve-2020-0796-poc

An unauthenticated PoC for CVE-2020-0796

exploitationpayload-generationpenetration-testing+2
226 years ago
struts2-jakarta-inject preview

struts2-jakarta-inject

GitHubgreynad/struts2-jakarta-inject

Golang exploit for CVE-2017-5638

exploitationpayload-generationpenetration-testing+2
28 years ago
nate158g-m-w-n-l-p-d-a-o-e preview

nate158g-m-w-n-l-p-d-a-o-e

GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

exploit-frameworkspayload-generationpenetration-testing-frameworks+3
124 years ago
ms09-050-CVE-2009-3103-exploit preview

ms09-050-CVE-2009-3103-exploit

GitHubnicolasdamians/ms09-050-cve-2009-3103-exploit

Automated exploit wrapper for MS09-050 (CVE-2009-3103) targeting SMBv2 on Windows Vista/Server 2008. Generates shellcode, builds exploit, and creates…

educationexploitationpayload-generation+3
8 months ago
HeimShell preview

HeimShell

GitHubsuperswan/heimshell

CVE-2023-5180 LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2025-14700-poc preview

CVE-2025-14700-poc

GitHubnosiume/cve-2025-14700-poc

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1

exploitationpayload-generationpenetration-testing+3
18 months ago
Previous1234Next