Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
179 results
Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution preview

Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution

GitHubtolu12wani/demonstration-of-cve-2023-38831-via-reverse-shell-execution

This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task…

educationexploitationpayload-generation+3
1 year ago
BlockchainC2 preview

BlockchainC2

GitHubxpn/blockchainc2

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

command-and-controlexploitationpayload-development+2
797 years ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubdairrow/cve-2025-31161

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

authenticationexploitationpayload-development+5
17 months ago
CVE-2023-33243 preview

CVE-2023-33243

GitHubredteampentesting/cve-2023-33243

PoC for login with password hash in STARFACE

authenticationexploitationpassword-attacks+3
13 years ago
Next.js-Middleware-Bypass-CVE-2025-29927- preview

Next.js-Middleware-Bypass-CVE-2025-29927-

GitHubpouriam23/next.js-middleware-bypass-cve-2025-29927-

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

ctfeducationlabs-practice+3
21 year ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5545 months ago
BoxPwnr preview

BoxPwnr

GitHub0ca/boxpwnr

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

ai-securityctfeducation+8
4501 month ago
wafparan01d3 preview

wafparan01d3

GitHubalt3kx/wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

configuration-auditingdefensive-toolspenetration-testing+2
244 years ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubygouzerh/cve-2017-12617

Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018

educationexploitationpayload-generation+3
27 years ago
CVE-2025-55182-Lab preview

CVE-2025-55182-Lab

GitHubmacaroniwdcheese/cve-2025-55182-lab

Local lab for understanding CVE-2025-55182 RCE in React Server Components/Next.js. Includes a deliberately vulnerable app and optional scanner helper…

ctfeducationlabs-practice+3
8 months ago
CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass preview
Archived

CVE-2019-6340-Drupal-8.6.9-REST-Auth-Bypass

GitHubdevdungeon/cve-2019-6340-drupal-8.6.9-rest-auth-bypass

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

educationexploitationpayload-generation+3
27 years ago
CVE-2025-60375 preview

CVE-2025-60375

GitHubajansha/cve-2025-60375

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

authenticationexploitationpenetration-testing+2
10 months ago
dh-CVE_2016_2098 preview

dh-CVE_2016_2098

GitHubhderms/dh-cve_2016_2098

Proof of concept showing how CVE-2016-2098 leads to remote code execution

educationexploitationpenetration-testing+2
310 years ago
cybersecurity-struts2 preview

cybersecurity-struts2

GitHubsighup1/cybersecurity-struts2

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

educationexploitationpayload-development+3
17 years ago
CVE-2024-48990-Exploit preview

CVE-2024-48990-Exploit

GitHubally-petitt/cve-2024-48990-exploit

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

exploitationpayload-developmentpenetration-testing+3
51 year ago
Titanis preview

Titanis

GitHubtrustedsec/titanis

Windows protocol library, including SMB and RPC implementations, among others.

authenticationcryptographyexploitation+7
83114 days ago
CVE-2023-27350-PoC preview

CVE-2023-27350-PoC

GitHub0xb0y426/cve-2023-27350-poc

Proof-of-concept exploit for CVE-2023-27350 authentication bypass in PaperCut MF/NG, allowing unauthenticated interaction with vulnerable print…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
Log4j-CVE-2021-44228 preview

Log4j-CVE-2021-44228

GitHubdark-ninja10/log4j-cve-2021-44228

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
Previous1…678…10Next