Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
85 results
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k3 days ago
chisel preview

chisel

GitHubjpillora/chisel

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

command-and-controldata-exfiltrationgeneral-purpose-utilities+8
16.5k6 days ago
CVE-2021-31166 preview
Archived

CVE-2021-31166

GitHub0vercl0k/cve-2021-31166

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

binary-exploitationexploitationremote-access-tool+2
8275 years ago
CVE-2022-46169 preview

CVE-2022-46169

GitHubantisecc/cve-2022-46169

Exploit for CVE-2022-46169 in Cacti, enabling unauthenticated remote code execution via crafted HTTP requests to remote_agent.php.

command-and-controlexploitationremote-access-tool+2
3 years ago
cloudflared preview

cloudflared

GitHubcloudflare/cloudflared

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

api-securitycloud-infrastructure-securitycloud-security+3
15.5k4 days ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubludovicpatho/cve-2021-41773

The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.

educationexploitationpenetration-testing+3
53 years ago
CVE-2024-36401-PoC preview

CVE-2024-36401-PoC

GitHuby1s4s/cve-2024-36401-poc

Proof-of-concept exploit for CVE-2024-36401 enabling remote code execution via HTTP requests with reverse shell payload generation and Base64…

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2015-1635-POC preview

CVE-2015-1635-POC

GitHubh3x0v3rl0rd/cve-2015-1635-poc

Proof-of-concept exploit for CVE-2015-1635 (MS15-034), demonstrating remote code execution in HTTP.sys via crafted HTTP requests on vulnerable…

exploitationpenetration-testingremote-access-tool+2
22 years ago
apache_normalize_path preview

apache_normalize_path

GitHubzeop-cybersec/apache_normalize_path

Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)

exploit-frameworkspayload-developmentpenetration-testing+3
124 years ago
CVE-2021-31166-exploit preview

CVE-2021-31166-exploit

GitHubiranzai/cve-2021-31166-exploit

Exploit for CVE-2021-31166 targeting HTTP Protocol Stack RCE in Windows 10 and Server versions 2004/20H2, enabling remote code execution via crafted…

exploitationpenetration-testingremote-access-tool+2
24 years ago
HTTP-revshell preview

HTTP-revshell

GitHub3v4si0n/http-revshell

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

command-and-controlids-ips-evasionpayload-generation+4
5982 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubverylazytech/cve-2024-23692

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

exploitationpenetration-testingreconnaissance+3
481 year ago
CVE-2026-23744-PoC preview

CVE-2026-23744-PoC

GitHubboroeurnprach/cve-2026-23744-poc

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by…

exploitationpayload-generationpenetration-testing+3
92 months ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubscirusvulgaris/cve-2017-12617

Python exploit for Apache Tomcat CVE-2017-12617 RCE vulnerability. Checks targets, generates webshells, and provides remote shell access on systems…

exploitationpayload-generationpenetration-testing+3
2 years ago
sshimpanzee preview

sshimpanzee

GitHublexfo/sshimpanzee

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

command-and-controldns-analysisnetwork-security+4
2941 year ago
Fenrir preview

Fenrir

GitHubnccgroup/fenrir

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

command-and-controllateral-movementpenetration-testing+3
6711 years ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubcyberheartmi9/cve-2017-12617

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution

exploitationpayload-generationpenetration-testing+3
3998 years ago
Http-Asynchronous-Reverse-Shell preview
Archived

Http-Asynchronous-Reverse-Shell

GitHubonsec-fr/http-asynchronous-reverse-shell

[POC] Asynchronous reverse shell using the HTTP protocol.

command-and-controldata-exfiltrationids-ips-evasion+7
2721 year ago
Previous12345Next