Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
CVE-2026-67206 preview

CVE-2026-67206

GitHubanirbala98/cve-2026-67206

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

educationexploitationpayload-development+3
1
14 days ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubkatransefa/cve-2026-13714

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

exploitationpayload-developmentpenetration-testing+2
17 days ago
CVE-2026-17544 preview

CVE-2026-17544

GitHubr2qa/cve-2026-17544

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

binary-exploitationexploitationpayload-development+4
19 days ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
23 days ago
Shadow-Vault preview

Shadow-Vault

GitHubjenderal92/shadow-vault

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

authentication-authorizationemail-securityidentity-access-management+3
3 months ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubc0gnit00/cve-2025-9074

PHP poc, exploit for CVE-2025-9074

cloud-securitycommand-and-controlcontainer-escape+8
3 months ago
CVE-2025-62429 preview

CVE-2025-62429

GitHubdrkim-dev/cve-2025-62429

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

code-analysisexploitationpayload-development+5
15 months ago
osTicketFileReadIntoRCE preview

osTicketFileReadIntoRCE

GitHubclarissss/osticketfilereadintorce

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket…

educationexploitationpayload-development+6
6 months ago
casper-shell preview

casper-shell

GitLabr3dteam/casper-shell

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

data-exfiltrationpenetration-testingpersistence-mechanisms+4
8 months ago
ctf-cve-2019-11043 preview

ctf-cve-2019-11043

GitHuba1ex-var1amov/ctf-cve-2019-11043

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

cloud-securitycontainer-securityctf+8
1 year ago
php-reverse-shell preview

php-reverse-shell

GitHubpentestmonkey/php-reverse-shell

PHP script that establishes a reverse shell from a target server to the attacker's machine, enabling remote command execution and post-exploitation…

exploitationpenetration-testingpost-exploitation+2
2.9k2 years ago
phpsploit preview

phpsploit

GitHubnil0x42/phpsploit

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

command-and-controlexploit-frameworkspayload-development+6
2.5k2 years ago
revshell preview

revshell

GitHubprodigiousmind/revshell

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

exploitationpayload-generationpenetration-testing+3
43 years ago
C99Shell-PHP7 preview

C99Shell-PHP7

GitHubpinoywh1z/c99shell-php7

PHP 7 and safe-build Update of the popular C99 variant of PHP Shell.

payload-generationpenetration-testingpost-exploitation+2
1523 years ago
bantam preview

bantam

GitHubgellin/bantam

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

command-and-controlencryption-decryption-toolsids-ips-evasion+5
2823 years ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
834 years ago
php_reverse_shell preview

php_reverse_shell

GitHubh3x0v3rl0rd/php_reverse_shell

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

command-and-controlpenetration-testingpost-exploitation+3
5 years ago
php-reverse-shell preview

php-reverse-shell

GitHubh3x0v3rl0rd/php-reverse-shell

PHP reverse shell script for establishing a remote TCP connection, enabling command execution on a target web server.

penetration-testingpost-exploitationred-teaming+2
5 years ago
Previous12Next