Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
CVE-2021-2394 preview

CVE-2021-2394

GitHublz2y/cve-2021-2394

Proof-of-concept exploit for CVE-2021-2394, a remote code execution vulnerability in Oracle WebLogic Server. Uses LDAP or RMI deserialization to…

educationexploitationpayload-generation+3
40
4 years ago
CVE-2021-44228-PoC preview

CVE-2021-44228-PoC

GitHubsunnyvale-it/cve-2021-44228-poc

CVE-2021-44228 (Log4Shell) Proof of Concept

educationexploitationpayload-generation+3
84 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubfuture-client/cve-2021-44228

Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)

exploitationpayload-generationpenetration-testing+3
664 years ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
115 days ago
CVE-2021-44228_Example preview

CVE-2021-44228_Example

GitHubchilliwebs/cve-2021-44228_example

Docker-based reproduction environment for CVE-2021-44228 (Log4Shell) with marshalsec LDAP server, exploit web server, and vulnerable Java application…

dynamic-analysis-sandboxingexploitationpayload-generation+2
14 years ago
CVE-2021-44228-Demo preview

CVE-2021-44228-Demo

GitHubmzlogin/cve-2021-44228-demo

Apache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP

educationexploitationpayload-generation+3
24 years ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k2 months ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9655 days ago
Weblogic-CVE-2023-21839 preview

Weblogic-CVE-2023-21839

GitHubdxask88ma/weblogic-cve-2023-21839

Java-based exploit for CVE-2023-21839 targeting Oracle WebLogic Server versions 12.2.1.3.0 and 12.2.1.4.0 via LDAP injection for remote code…

exploitationpayload-generationpenetration-testing+3
2413 years ago
log4j-poc preview

log4j-poc

GitHubcyberxml/log4j-poc

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

educationexploitationlabs-practice+4
723 years ago
POC_CVE-2023-21839 preview

POC_CVE-2023-21839

GitHubhouqe/poc_cve-2023-21839

Python proof-of-concept exploit for CVE-2023-21839 targeting WebLogic servers via LDAP injection for unauthenticated remote code execution.

exploitationpayload-generationpenetration-testing+2
193 years ago
CVE-2024-21006_jar preview

CVE-2024-21006_jar

GitHublightr3d/cve-2024-21006_jar

Java-based exploit for CVE-2024-21006, delivering a payload via LDAP to a target IP and port. Includes compiled JAR and source for customization.

exploitationpayload-generationpenetration-testing+2
172 years ago
PAYLOAD-LISTS preview

PAYLOAD-LISTS

GitHubnu11secur1ty/payload-lists

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

curated-resourceseducationpayload-generation+3
413 days ago
Apache-Log4j-POC preview

Apache-Log4j-POC

GitHubbadb33f/apache-log4j-poc

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

command-and-controlexploitationpayload-generation+2
34 years ago
EXPLOIT-CVE-2021-44228 preview

EXPLOIT-CVE-2021-44228

GitHubjoaovicdev/exploit-cve-2021-44228

Docker-based educational lab demonstrating Log4Shell (CVE-2021-44228) RCE exploitation with a vulnerable Java application, LDAP redirector, and…

educationexploitationlabs-practice+3
4 months ago
CVE-2021-44228_Log4Shell preview

CVE-2021-44228_Log4Shell

GitHubvutiendat323/cve-2021-44228_log4shell

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

educationexploitationlabs-practice+3
3 months ago
CVE-2021-44228_dockernize preview

CVE-2021-44228_dockernize

GitHubqw3rtyou/cve-2021-44228_dockernize

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

educationexploitationlabs-practice+3
11 year ago
CVE-2021-44228-Apache-Log4j-Rce preview

CVE-2021-44228-Apache-Log4j-Rce

GitHubyuuki1967/cve-2021-44228-apache-log4j-rce

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection, LDAP reference server, and WAF bypass techniques for testing Log4j RCE…

exploitationpayload-generationpenetration-testing+3
8 months ago
Previous12Next