Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
683 results
CVE-2018-3191 preview

CVE-2018-3191

GitHubjas502n/cve-2018-3191

Exploit for CVE-2018-3191 targeting Oracle WebLogic Server via T3 protocol, enabling unauthenticated remote code execution with JNDI payload…

command-and-controlexploitationpayload-generation+3
68
7 years ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
sak1to-shell preview

sak1to-shell

GitHubd4rk007/sak1to-shell

Multi-threaded, multi-os/platform (Linux/Windows) c2 server and Windows reverse TCP shell client both written in C.

command-and-controlpayload-generationpost-exploitation+2
1204 years ago
cve-2021-21985_exp preview

cve-2021-21985_exp

GitHubxnianq/cve-2021-21985_exp

cve-2021-21985 exploit

command-and-controlexploitationpayload-generation+3
1154 years ago
CVE-2020-14756 preview

CVE-2020-14756

GitHuby4er/cve-2020-14756

WebLogic T3/IIOP RCE ExternalizableHelper.class of coherence.jar

exploitationpayload-generationremote-access-tool+2
795 years ago
CVE-2018-2628 preview

CVE-2018-2628

GitHubjas502n/cve-2018-2628

Weblogic 反序列化漏洞(CVE-2018-2628)

exploitationpayload-generationpenetration-testing+3
1077 years ago
wordpress-shell preview

wordpress-shell

GitHubleonjza/wordpress-shell

Cheap & Nasty Wordpress Command Execution Shell

command-and-controlexploitationpayload-generation+3
927 years ago
Shelly preview

Shelly

GitHubtegal1337/shelly

Simple Backdoor Manager with Python (based on weevely)

payload-generationpenetration-testingremote-access-tool+1
971 year ago
CVE-2017-7269-Echo-PoC preview

CVE-2017-7269-Echo-PoC

GitHublcatro/cve-2017-7269-echo-poc

CVE-2017-7269 回显PoC ,用于远程漏洞检测..

exploitationpayload-generationpenetration-testing+3
897 years ago
SlackShell preview

SlackShell

GitHubbkup/slackshell

PowerShell to Slack C2

command-and-controlpayload-developmentpenetration-testing+3
1078 years ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHubpimps/cve-2017-1000486

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

exploitationpayload-generationpenetration-testing+3
952 years ago
Log4jHorizon preview

Log4jHorizon

GitHubpuzzlepeaches/log4jhorizon

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

exploitationpayload-developmentpenetration-testing+4
1204 years ago
CVE-2019-2890 preview

CVE-2019-2890

GitHubl1nk3rlin/cve-2019-2890

PoC exploit for CVE-2019-2890 targeting Oracle WebLogic, using ysoserial JRMP payload for remote command execution via serialized object…

command-and-controlexploitationpayload-generation+3
856 years ago
QuickResponseC2 preview

QuickResponseC2

GitHubkimd155/quickresponsec2

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…

command-and-controlpayload-generationpenetration-testing+2
544 months ago
CVE-2020-7931 preview

CVE-2020-7931

GitHubgquere/cve-2020-7931

Hacking Artifactory with server side template injection

exploitationpayload-developmentpenetration-testing+3
506 years ago
CVE-2025-0282-Ivanti-exploit preview

CVE-2025-0282-Ivanti-exploit

GitHubabsholi7ly/cve-2025-0282-ivanti-exploit

CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overflow exploit.

command-and-controlexploitationpayload-development+3
531 year ago
cve-2019-0708_bluekeep_rce preview

cve-2019-0708_bluekeep_rce

GitHubcoolboy4me/cve-2019-0708_bluekeep_rce

it works on xp (all version sp2 sp3)

exploitationpayload-developmentpenetration-testing+3
757 years ago
DaaC2 preview

DaaC2

GitHubcrawl3r/daac2

Discord as a C2

command-and-controlpayload-generationred-teaming+1
515 years ago
Previous1…678…38Next