Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
161 results
TornadoRevC2 preview

TornadoRevC2

GitHubkamalx06/tornadorevc2

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

command-and-controlinformation-gatheringlateral-movement+8
24
2 days ago
CVE-2026-44402 preview

CVE-2026-44402

GitHub0xcyp1337/cve-2026-44402

Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

exploitationpenetration-testingred-teaming+3
7 days ago
CVE-2026-34197-PoC preview

CVE-2026-34197-PoC

GitHubnirvanasec/cve-2026-34197-poc

Proof-of-concept exploit for CVE-2026-34197, an RCE in Apache ActiveMQ via Jolokia's addNetworkConnector, with technical notes and reverse shell…

exploitationpenetration-testingred-teaming+3
9 days ago
SmarterMail-CVE-2026-24423 preview

SmarterMail-CVE-2026-24423

GitHubcyberalp0/smartermail-cve-2026-24423

Exploit for CVE-2026-24423 — a critical unauthenticated RCE in SmarterMail's ConnectToHub API. Affects all builds prior to 9511.

exploitationpenetration-testingred-teaming+3
11 days ago
CVE-2026-33017-PoC-Reverse-Shell preview

CVE-2026-33017-PoC-Reverse-Shell

GitHubahseven/cve-2026-33017-poc-reverse-shell

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow, enabling reverse shell via malicious CustomComponent payload.

exploitationpenetration-testingred-teaming+3
16 days ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubgabrielunknown/cve-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

exploitationpenetration-testingred-teaming+3
416 days ago
Log4jHorizon preview

Log4jHorizon

GitHubpuzzlepeaches/log4jhorizon

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

exploitationpayload-developmentpenetration-testing+4
1204 years ago
CVE-2026-22444 preview

CVE-2026-22444

GitHubbfdfhdsfdd-crypto/cve-2026-22444

Exploit for Apache Solr CVE-2026-22444, leveraging UNC path injection and SMB server to achieve remote code execution via malicious configset and…

exploitationpenetration-testingred-teaming+3
7 months ago
lab-annie preview

lab-annie

GitHublincolino/lab-annie

Automates exploitation of CVE-2020-13160, a critical remote code execution vulnerability in AnyDesk 5.5.2, enabling penetration testers to validate…

exploitationpenetration-testingred-teaming+2
18 days ago
cve-2022-42475-poc preview

cve-2022-42475-poc

GitHubull0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

exploitationpenetration-testingred-teaming+3
120 days ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k5 days ago
ReverseSocks5 preview

ReverseSocks5

GitHubacebond/reversesocks5

Single executable reverse SOCKS5 proxy written in Golang.

penetration-testingpost-exploitationred-teaming+1
1595 months ago
OffensiveLua preview

OffensiveLua

GitHubhackerhouse-opensource/offensivelua

Offensive Lua.

ids-ips-evasionpassword-attackspayload-development+6
2257 months ago
USBArmyKnife preview

USBArmyKnife

GitHubi-am-shodan/usbarmyknife

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

bluetooth-securitydata-exfiltrationhardware-hacking+8
2.9k9 days ago
Java-Servlets-Shell preview

Java-Servlets-Shell

GitHubmbadanoiu/java-servlets-shell

JSP-less Java Servlets Backdoor inspired by https://www.redteam-pentesting.de/files/redteam-jboss.tar.gz

command-and-controlexploitationpenetration-testing+3
11 year ago
Hadoop-Yarn-ResourceManager-RCE preview

Hadoop-Yarn-ResourceManager-RCE

GitHubal1ex/hadoop-yarn-resourcemanager-rce

Hadoop Yan ResourceManager unauthorized RCE

exploitationpenetration-testingred-teaming+3
394 years ago
phantap preview

phantap

GitHubnccgroup/phantap

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

ids-ips-evasionlateral-movementnetwork-mapping+4
62611 months ago
php-8.1.0-dev-backdoor-rce preview

php-8.1.0-dev-backdoor-rce

GitHubflast101/php-8.1.0-dev-backdoor-rce

PHP 8.1.0-dev Backdoor System Shell Script

exploitationpenetration-testingred-teaming+2
945 years ago
Previous12…9Next