Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
917 results
PayloadAutomation preview

PayloadAutomation

GitHubemcghee/payloadautomation

Automates Cobalt Strike payload development, testing, and deployment via a Python-to-Sleep bridge; includes artifact inspection, IoC tracking, and…

command-and-controlioc-managementpayload-development+3
120
4 years ago
harpyTools preview

harpyTools

GitHubjssngc/harpytools

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

command-and-controlexploitationlateral-movement+6
204 days ago
turing-machine preview

turing-machine

GitHubintrinsic-propensity/turing-machine

Python implementation of Minsky's Universal Turing Machine with a built-in exploit demonstrating arbitrary code execution (CVE-2021-32471) for…

binary-exploitationeducationexploitation+4
794 years ago
CVE-2007-2447-in-Python preview

CVE-2007-2447-in-Python

GitHubziemni/cve-2007-2447-in-python

Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).

command-and-controlexploitationpayload-generation+3
35 years ago
CVE-2021-38295-PoC preview

CVE-2021-38295-PoC

GitHubprofessionallyevil/cve-2021-38295-poc

A simple Python proof of concept for CVE-2021-38295.

exploitationpayload-generationpenetration-testing+2
34 years ago
CVE-2025-34037 preview

CVE-2025-34037

GitHubtaxanehh/cve-2025-34037

Python port of the Linksys tmUnblock.cgi RCE exploit

command-and-controleducationembedded-systems-security+4
5 months ago
CVE-2023-27163 preview

CVE-2023-27163

GitHubhamibubu/cve-2023-27163

Python implementation of CVE-2023-27163

exploitationpayload-generationpenetration-testing+2
2 years ago
CVE-2016-10033 preview
Archived

CVE-2016-10033

GitHubgeneraltesler/cve-2016-10033

RCE against WordPress 4.6; Python port of https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html

exploitationpayload-generationpenetration-testing+3
99 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtiepologian/cve-2023-23397

Proof of Concept for CVE-2023-23397 in Python

email-securityexploitationpayload-generation+3
253 years ago
cve-2019-3398 preview

cve-2019-3398

GitHubsuperevr/cve-2019-3398

Python script to exploit confluence path traversal vulnerability cve-2019-3398

exploitationpayload-generationpenetration-testing+2
157 years ago
CVE-2026-23744-MCPJAM-RCE-exploit preview

CVE-2026-23744-MCPJAM-RCE-exploit

GitHubdahalsamir/cve-2026-23744-mcpjam-rce-exploit

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an…

exploitationpayload-generationpenetration-testing+2
3 months ago
CVE-2023-27372-POC preview

CVE-2023-27372-POC

GitHubizzz0/cve-2023-27372-poc

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

exploitationinformation-gatheringpayload-generation+3
23 years ago
CVE-2022-22963-PoC preview

CVE-2022-22963-PoC

GitHublemmyz4n3771/cve-2022-22963-poc

CVE-2022-22963 RCE PoC in python

exploitationpayload-generationpenetration-testing+2
43 years ago
Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE preview

Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE

GitHubrandallbanner/spring-cloud-function-vulnerability-cve-2022-22963-rce

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

exploitationpayload-generationpenetration-testing+3
43 years ago
CVE-2025-59528-PoC preview

CVE-2025-59528-PoC

GitHubmananispiwpiw/cve-2025-59528-poc

CVE-2025-59528 Proof of Concept

educationexploitationpayload-generation+3
14 months ago
CVE-2012-2982-Webmin-RCE preview

CVE-2012-2982-Webmin-RCE

GitHubjrrooot/cve-2012-2982-webmin-rce

Python PoC for Webmin 1.580 Remote Command Execution (CVE-2012-2982)

educationexploitationpayload-generation+3
18 months ago
CrushFTP-CVE-2024-4040-illdeed preview

CrushFTP-CVE-2024-4040-illdeed

GitHubill-deed/crushftp-cve-2024-4040-illdeed

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

authenticationexploitationpayload-generation+3
1 year ago
CVE-2015-3306 preview

CVE-2015-3306

GitHubdonmedfor/cve-2015-3306

Python PoC exploit for CVE-2015-3306 ProFTPD directory traversal. Copies files and drops a PHP backdoor into webroot for remote command execution via…

exploitationpayload-generationpenetration-testing+2
1 year ago
Previous12…51Next