Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
84 results
weaponised-XSS-payloads preview

weaponised-XSS-payloads

GitHubhakluke/weaponised-xss-payloads

XSS payloads designed to turn alert(1) into P1

exploitationpayload-developmentpayload-generation+3
1.4k
3 years ago
shad0w preview

shad0w

GitHubbats3c/shad0w

A post exploitation framework designed to operate covertly on heavily monitored environments

command-and-controlexploit-frameworkspayload-generation+2
2.2k5 years ago
bantam preview

bantam

GitHubgellin/bantam

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

command-and-controlencryption-decryption-toolsids-ips-evasion+5
2824 years ago
Livepyre preview

Livepyre

GitHubsynacktiv/livepyre

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.

command-and-controlexploitationpayload-generation+3
1502 months ago
laravel-crypto-killer preview

laravel-crypto-killer

GitHubsynacktiv/laravel-crypto-killer

A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.

encryption-decryption-toolsexploitationpayload-generation+2
1469 months ago
c2-cloud preview

c2-cloud

GitHubgovindasamyarun/c2-cloud

The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised…

command-and-controlexploit-frameworkspayload-generation+4
1282 years ago
React2Shell preview

React2Shell

GitHubshyambhanushali/react2shell

React2Shell is a Python-based proof-of-concept tool designed to exploit CVE-2025-55182 and CVE-2025-66478, both impacting Next.js applications using…

educationexploitationpayload-generation+3
1310 months ago
CVE-2024-25600-Bricks-Builder-plugin-for-WordPress preview

CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

GitHubtornad0007/cve-2024-25600-bricks-builder-plugin-for-wordpress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for…

command-and-controlexploitationpayload-generation+3
82 years ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

ctfeducationexploitation+5
64 months ago
CVE-2024-50379-POC preview

CVE-2024-50379-POC

GitHubdragonked2/cve-2024-50379-poc

This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a…

educationexploitationpayload-generation+3
41 year ago
CVE-2025-54068 preview

CVE-2025-54068

GitHubhaxorstars/cve-2025-54068

A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.

exploitationpayload-generationpenetration-testing+2
56 months ago
CVE-2022-45701 preview

CVE-2022-45701

GitHubgeniuszly/cve-2022-45701

it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script…

educationexploitationiot-security+6
52 years ago
CVE-2024-27130 preview

CVE-2024-27130

GitHubd0rb/cve-2024-27130

This Python script is designed as a proof-of-concept (PoC) for the CVE-2024-27130 vulnerability in QNAP QTS

exploitationpayload-generationpenetration-testing+3
22 years ago
ComfyUIrce preview

ComfyUIrce

GitHubjcaz2378/comfyuirce

Proof-of-concept exploit payload for CVE-2025-67303 targeting Git repositories. Designed for security testing and vulnerability validation.

exploitationpayload-generationpenetration-testing+2
4 months ago
CVE-2024-5084-Red-Team preview

CVE-2024-5084-Red-Team

GitHubredteamblueteam/cve-2024-5084-red-team

Proof-of-concept exploit for CVE-2024-5084 (Hash Form WordPress plugin) demonstrating unauthenticated file upload to RCE. Designed for educational…

educationexploitationlabs-practice+4
18 months ago
PHP-REVERSE-SHELL preview

PHP-REVERSE-SHELL

GitLabs_r_e_e_r_a_j/php-reverse-shell

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

command-and-controleducationids-ips-evasion+6
11 year ago
Modified-CVE-2019-15107 preview

Modified-CVE-2019-15107

GitHubcdedmondson/modified-cve-2019-15107

Modified exploit for CVE-2019-15107 with a Perl reverse shell payload. Designed for penetration testing of the targeted web application vulnerability.

exploitationpayload-generationpenetration-testing+2
5 years ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubsoch4n/cve-2018-7600

Python exploit for CVE-2018-7600 (Drupalgeddon2) targeting remote code execution in Drupal CMS. Designed for penetration testing and vulnerability…

exploitationpayload-generationpenetration-testing+2
8 years ago
Previous12345Next