Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
822 results
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
1
1 month ago
libextractor-ole2-rce preview

libextractor-ole2-rce

GitHubhaitam-lazaar/libextractor-ole2-rce

PoC for a Critical stack-based buffer overflow in GNU libextractor ≤ 1.14. A malicious .doc file triggers an unbounded VLA allocation causing…

binary-exploitationexploitationlabs-practice+4
18 days ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubkondordevsecuritycorp/cve-2026-34197

Exploit for Apache ActiveMQ RCE via Jolokia API (CVE-2026-34197) with command output capture, mass scanning, and auto-exploitation.

exploitationlabs-practicepayload-generation+4
25 months ago
horrors-log4shell preview

horrors-log4shell

GitHubtasooshi/horrors-log4shell

A micro lab for CVE-2021-44228 (log4j)

exploitationlabs-practicepayload-generation+3
24 years ago
CVE-2017-12611_Exploit preview

CVE-2017-12611_Exploit

GitHubzeynepsilao/cve-2017-12611_exploit

RCE project

exploitationlabs-practicepayload-generation+3
1 year ago
CVE-2026-48356 preview

CVE-2026-48356

GitHubabraxas/cve-2026-48356

Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.

exploitationlabs-practicepayload-generation+5
8 days ago
react2shellpoc preview

react2shellpoc

GitHubsurajhacx/react2shellpoc

react2shell CVE-2025-55182 PoC

educationexploitationpayload-generation+3
3110 months ago
nishang preview

nishang

GitHubsamratashok/nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

command-and-controldata-exfiltrationexploitation+9
10.1k3 years ago
CVE-2025-55182_liyon preview

CVE-2025-55182_liyon

GitHubhujiaozhuzhu/cve-2025-55182_liyon

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

command-and-controleducationexploitation+7
6 months ago
vulnerable-PDF preview

vulnerable-PDF

GitHubnu11secur1ty/vulnerable-pdf

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

educationlabs-practicepayload-generation+3
112 years ago
r2s preview

r2s

GitHubzamdevio/r2s

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

command-and-controlexploitationinformation-gathering+5
210 months ago
log4shell4shell preview

log4shell4shell

GitHubsuuhm/log4shell4shell

Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell

educationexploitationpayload-generation+3
54 years ago
CVE-2022-22965-PoC preview

CVE-2022-22965-PoC

GitHubkirill89/cve-2022-22965-poc

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) demonstrating remote code execution via Tomcat AccessLogValve manipulation. Includes…

educationexploitationpayload-generation+3
324 years ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubmariomamo/cve-2022-22965

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) with a vulnerable Spring Boot application, Python exploit script, and Docker-based lab…

educationexploitationpayload-generation+3
54 years ago
CVE-2014-6271 preview

CVE-2014-6271

GitHubim2sinister/cve-2014-6271

Python exploit for CVE-2014-6271 (Shellshock) that injects malicious HTTP headers into CGI scripts to execute arbitrary commands via Bash environment…

educationexploitationpayload-generation+3
12 months ago
CVE-2020-15227 preview

CVE-2020-15227

GitHublangriklol/cve-2020-15227

CVE-2020-15227 exploit

educationexploitationpayload-generation+3
15 years ago
CVE-2021-44228_dockernize preview

CVE-2021-44228_dockernize

GitHubqw3rtyou/cve-2021-44228_dockernize

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

educationexploitationlabs-practice+3
11 year ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

command-and-controleducationexploitation+7
10 months ago
Previous12…46Next