Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
Embedded-PDF preview

Embedded-PDF

GitHubjasmoon99/embedded-pdf

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

command-and-controleducationexploitation+6
715 years ago
Embedded-Backdoor-Connection preview

Embedded-Backdoor-Connection

GitHubomarothmann/embedded-backdoor-connection

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

command-and-controleducationexploitation+5
84 years ago
CVE-2024-4323-Exploit-POC preview

CVE-2024-4323-Exploit-POC

GitHubskilfoy/cve-2024-4323-exploit-poc

This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code…

exploitationpayload-generationpenetration-testing+3
152 years ago
CVE-2025-1913-PoC preview

CVE-2025-1913-PoC

GitHubs0haib518-ksa/cve-2025-1913-poc

A PoC demonstrating CVE-2025-1913, showing how the plugin’s unsafe unserialize handling can lead to high-impact behavior in controlled environments.…

educationexploitationlabs-practice+3
28 months ago
vsftpd-2.3.4---Backdoor-Command-Execution preview

vsftpd-2.3.4---Backdoor-Command-Execution

GitHubtshaq17/vsftpd-2.3.4---backdoor-command-execution

vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step,…

educationexploitationpayload-generation+3
7 months ago
Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution preview

Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution

GitHubtolu12wani/demonstration-of-cve-2023-38831-via-reverse-shell-execution

This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task…

educationexploitationpayload-generation+3
1 year ago
log4j-CVE-2021-44228-test preview

log4j-CVE-2021-44228-test

GitHubkossatzd/log4j-cve-2021-44228-test

demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability

educationexploitationpayload-generation+3
4 years ago
Ios-Safari-Mallicous-Extension-Example preview

Ios-Safari-Mallicous-Extension-Example

GitHubspiralbl0ck/ios-safari-mallicous-extension-example

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

exploitationinformation-gatheringios-security+3
2 years ago
Stitch preview

Stitch

GitHubnathanlopez/stitch

Python Remote Administration Tool (RAT)

educationpassword-crackingpayload-generation+2
3.7k9 years ago
donut preview

donut

GitHubthewover/donut

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

exploitationids-ips-evasionmemory-forensics+7
4.7k1 year ago
CVE-2018-20250 preview

CVE-2018-20250

GitHubwyatu/cve-2018-20250

exp for https://research.checkpoint.com/extracting-code-execution-from-winrar

exploitationpayload-generationpenetration-testing+3
4937 years ago
BoxPwnr preview

BoxPwnr

GitHub0ca/boxpwnr

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

ai-securityctfeducation+8
4501 month ago
mkPIVM preview

mkPIVM

GitHubd7ead/mkpivm

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

exploitationmalware-analysispayload-generation+3
39429 days ago
Mega-Bot preview

Mega-Bot

GitHubaron-tn/mega-bot

[NEW] : Mega Bot ☣ Scanner & Auto Exploiter

exploitationinformation-gatheringosint+8
1656 years ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1287 years ago
haptyc preview

haptyc

GitHubdefparam/haptyc

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

fuzzingpayload-generationpenetration-testing+1
934 years ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHubpimps/cve-2017-1000486

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

exploitationpayload-generationpenetration-testing+3
952 years ago
react2shellpoc preview

react2shellpoc

GitHubsurajhacx/react2shellpoc

react2shell CVE-2025-55182 PoC

educationexploitationpayload-generation+3
319 months ago
Previous12Next