Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
27 results
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k5 days ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
6 days ago
SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit preview

SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit

GitHubomribaso/sccm-cve-2026-47301-remote-code-execution-exploit

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

exploitationpayload-developmentpenetration-testing+3
888 days ago
secbutler preview

secbutler

GitHubthelicato/secbutler

The perfect butler for pentesters, bug-bounty hunters and security researchers

payload-generationpenetration-testingreconnaissance+2
9512 days ago
xss2shell preview

xss2shell

GitHub0xlipon/xss2shell

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

defensive-toolspayload-generationpenetration-testing+6
315 days ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

adversarial-attackcommand-and-controleducation+9
1.1k21 days ago
CVE-2026-58480 preview

CVE-2026-58480

GitHubshinthink/cve-2026-58480

Proof-of-concept exploit for unauthenticated remote code execution in Blocksy Companion Pro via double-extension file upload bypass.

exploitationpayload-generationpenetration-testing+3
329 days ago
CVE-2026-4883 preview

CVE-2026-4883

GitHubxshadow-here/cve-2026-4883

Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE

exploitationpayload-generationpenetration-testing+3
2 months ago
R2SAE preview

R2SAE

GitHuboscar-mine/r2sae

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

command-and-controlexploitationpayload-generation+5
3 months ago
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

ctfeducationexploitation+8
3 months ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
4 months ago
CVE-2021-41773_CVE-2021-42013 preview

CVE-2021-41773_CVE-2021-42013

GitHubls4ss/cve-2021-41773_cve-2021-42013

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution vulnerabilities (CVE-2021-41773, CVE-2021-42013).…

exploitationpayload-generationpenetration-testing+3
205 months ago
CVE-2025-55182-NextJS-Scanner-React2Shell-PoC preview

CVE-2025-55182-NextJS-Scanner-React2Shell-PoC

GitHubexrienz/cve-2025-55182-nextjs-scanner-react2shell-poc

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

command-and-controlexploitationpayload-generation+5
8 months ago
MassExploit-CVE-2024-4577 preview

MassExploit-CVE-2024-4577

GitHubcirqueiradev/massexploit-cve-2024-4577

Mass scanner and exploit tool for CVE-2024-4577, a PHP-CGI argument injection vulnerability, enabling automated detection and exploitation of…

exploitationpayload-generationpenetration-testing+3
58 months ago
RCE-CVE-2025-32710 preview

RCE-CVE-2025-32710

GitHubsincan2/rce-cve-2025-32710

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

exploitationpayload-generationpenetration-testing+6
51 year ago
ecp_slap preview

ecp_slap

GitHubzyn3rgy/ecp_slap

Proof-of-concept exploit for CVE-2020-0688 targeting on-prem Microsoft Exchange. Includes scanning, cookie harvesting, payload generation via…

exploitationpayload-generationpenetration-testing+3
111 year ago
CVE-2024-27198-RCE preview

CVE-2024-27198-RCE

GitHubcharondefalt/cve-2024-27198-rce

Exploit for JetBrains TeamCity authentication bypass (CVE-2024-27198) enabling remote code execution, with webshell upload and connection…

exploitationpayload-generationpenetration-testing+3
12 years ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
Previous12Next