Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
evilrdp preview

evilrdp

GitHubskelsec/evilrdp

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

command-and-controllateral-movementpenetration-testing+3
310
1 year ago
Log4j-JNDIServer preview

Log4j-JNDIServer

GitHubimmunityinc/log4j-jndiserver

This project will help to test the Log4j CVE-2021-44228 vulnerability.

command-and-controlexploitationpayload-generation+3
94 years ago
SecurityNotFound preview

SecurityNotFound

GitHubarchive-puma/securitynotfound

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

payload-generationremote-access-toolweb-security
914 years ago
GC2-sheet preview

GC2-sheet

GitHubloociprian/gc2-sheet

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

command-and-controldata-exfiltrationmalware-analysis+2
6583 months ago
Stitch preview

Stitch

GitHubnathanlopez/stitch

Python Remote Administration Tool (RAT)

educationpassword-crackingpayload-generation+2
3.7k9 years ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
5 months ago
spybrowse preview

spybrowse

GitHub1d8/spybrowse

Code developed to steal certain browser config files (history, preferences, etc)

data-exfiltrationinformation-gatheringmalware-analysis+2
636 years ago
pwnlift preview

pwnlift

GitHubrasta-mouse/pwnlift

Easy peasy file uploads

data-exfiltrationpenetration-testingremote-access-tool+2
443 months ago
hfs2 preview

hfs2

GitHubwgetnz/hfs2

CVE-2024-23692 | HFS 2.3m/2.4-RC07 RCE vulnerability fix

exploitationpenetration-testingremote-access-tool+2
12 days ago
NyxInvoke preview

NyxInvoke

GitHubblacksnufkin/nyxinvoke

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

command-and-controlexploitationids-ips-evasion+6
2431 year ago
Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit preview

Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit

GitHubicmpoff/apache-2.4.49-2.4.50-traversal-remote-code-execution-exploit

This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If…

exploit-frameworkspayload-developmentpenetration-testing-frameworks+3
14 years ago
CANalyse preview

CANalyse

GitHubkartheeklade/canalyse

A vehicle network analysis and attack tool.

exploitationhardware-hackingremote-access-tool
1185 years ago
CVE-2020-9484 preview

CVE-2020-9484

GitHubassassinukg/cve-2020-9484

Exploit script for CVE-2020-9484, a Tomcat session persistence deserialization vulnerability, enabling remote code execution via crafted session…

exploitationpayload-generationpenetration-testing+3
45 years ago
filessh preview

filessh

GitHubjayanaxhf/filessh

A fast and convenient TUI file browser for remote servers

network-securityremote-access-toolscripting-automation+1
2332 months ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubal1ex/cve-2022-1388

CVE-2022-1388 F5 BIG-IP iControl REST RCE

command-and-controlexploitationpenetration-testing+3
374 years ago
selenium-node-takeover-kit preview

selenium-node-takeover-kit

GitHubjonstratton/selenium-node-takeover-kit

A collection of selenium tests that might aid it takeover of a selenium node

command-and-controldata-exfiltrationexploit-frameworks+6
39 months ago
java-remote-class-loader preview

java-remote-class-loader

GitHubjoaovarelas/java-remote-class-loader

Client-server tool for remotely loading and executing Java bytecode via ClassLoader and Reflect API, with ChaCha20 encryption and keepalive…

command-and-controlencryption-decryption-toolsexploitation+3
344 years ago
parquet-rce-poc-CVE-2025-30065 preview

parquet-rce-poc-CVE-2025-30065

GitHubmouadk/parquet-rce-poc-cve-2025-30065

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

educationexploitationpayload-development+3
31 year ago
Previous123Next