Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
penelope preview

penelope

GitHubbrightio/penelope

Penelope Shell Handler

command-and-controlctfpayload-generation+5
2.0k1 day ago
ghostlock-a17 preview

ghostlock-a17

GitHubmobilehackinglab/ghostlock-a17

Kernel exploit for CVE-2026-43499 on Samsung Galaxy A17 achieving root via KDP bypass, KASLR recovery, and forged workqueue execution with persistent…

android-securitybinary-exploitationexploitation+4
2 days ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
9 days ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
10 days ago
CVE-2026-61511-PoC-Exploit preview

CVE-2026-61511-PoC-Exploit

GitHubtc4dy/cve-2026-61511-poc-exploit

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

database-securityexploitationnetwork-mapping+7
514 days ago
couchdb-exploit preview

couchdb-exploit

GitHubdarabium/couchdb-exploit

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

exploitationinformation-gatheringpenetration-testing+4
17 days ago
internal-penetration-testing-project-using-Metasploit preview

internal-penetration-testing-project-using-Metasploit

GitHubabdullah50i/internal-penetration-testing-project-using-metasploit

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

exploitationexploit-frameworksinformation-gathering+6
28 days ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
128 days ago
CVE-2026-63030-wp2r00t preview

CVE-2026-63030-wp2r00t

GitHubj4ck3lsyn-gen2/cve-2026-63030-wp2r00t

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

ctfeducationexploitation+5
61 month ago
unisoc-su preview

unisoc-su

GitHubskorpion96/unisoc-su

A method for CVE-2025-31710 and to connect to cmd_skt to obtain a root shell on unisoc unpatched models

android-securitybinary-exploitationcommand-and-control+7
1281 month ago
IS preview

IS

GitHubsadz1d/is

Metasploit-based exploit launcher for CVE-2017-7494 (Samba) with automated payload delivery and reverse shell session management.

command-and-controlexploitationpayload-generation+4
1 month ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub0x00jeff/cve-2025-27591

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

binary-exploitationexploitationpayload-development+5
151 month ago
RevShell preview

RevShell

GitHubdragon56yt/revshell

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

command-and-controldata-exfiltrationeducation+8
22 months ago
nim-shell preview

nim-shell

GitHubemrekybs/nim-shell

Reverse shell that can bypass windows defender detection

command-and-controlexploitationids-ips-evasion+5
1774 months ago
CVE-2025-55182-Toolbox preview

CVE-2025-55182-Toolbox

GitHublamaper/cve-2025-55182-toolbox
command-and-controlctfexploitation+6
18 months ago
CVE-2025-56383 preview

CVE-2025-56383

GitHubnewcomrade12211/cve-2025-56383

DLL hijacking to rev shell

binary-exploitationexploitationpayload-development+2
19 months ago
CVE-2021-1675 preview

CVE-2021-1675

GitHubdll00p/cve-2021-1675

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

exploitationlateral-movementpayload-generation+4
11 year ago
serverless-prey preview

serverless-prey

GitHubpumasecurity/serverless-prey

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

cloud-securityeducationexploitation+5
2481 year ago
Previous123Next