Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
BackDoorSim preview

BackDoorSim

GitHubhalildeniz/backdoorsim

Educational remote administration tool for learning RAT concepts, featuring file transfer, screenshot capture, system monitoring, and webcam access…

educationpenetration-testingpost-exploitation+2
122
2 years ago
XploitSPY preview

XploitSPY

GitHubxploitwizer-community/xploitspy

Cloud-based Android monitoring tool with GPS tracking, microphone recording, SMS/call logging, live notification capture, file explorer, and built-in…

android-securityeducationinformation-gathering+3
1.3k5 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcarlosaruy/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

ctfeducationexploitation+6
9 months ago
react2shell-interactive preview

react2shell-interactive

GitHubnathanj60/react2shell-interactive

CVE-2025-55182 Interactive PoC - React Server Components RCE - Educational Security Research

command-and-controleducationexploitation+5
9 months ago
CVE-2018-9276 preview

CVE-2018-9276

GitHubbardlaudian/cve-2018-9276

CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.

command-and-controleducationexploitation+5
2 months ago
n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613 preview

n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613

GitHubmbanyamer/n8n-authenticated-expression-injection-rce-cve-2025-68613

Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection

educationexploitationpayload-development+4
28 months ago
CVE-2025-8110 preview

CVE-2025-8110

GitHubixzodiak/cve-2025-8110

Gogs service Exploit and get the root user

ctfeducationexploitation+4
1 month ago
exploit-react-CVE-2025-55182 preview

exploit-react-CVE-2025-55182

GitHubtiger-foxx/exploit-react-cve-2025-55182

This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit…

educationexploitationpayload-development+5
58 months ago
ReactNext2Shell preview

ReactNext2Shell

GitHubfurkankayapinar/reactnext2shell

CVE-2025-55182 and CVE-2025-66478

educationexploitationlabs-practice+5
18 months ago
ToRat preview
Archived

ToRat

GitHubluantak/torat

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

command-and-controleducationpayload-generation+6
1.0k3 years ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

ctfeducationexploitation+5
63 months ago
cve-2025-32433_rce_exploit preview
Archived

cve-2025-32433_rce_exploit

GitHubgiriaryan694-a11y/cve-2025-32433_rce_exploit

This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHackMe lab environment.

binary-exploitationeducationexploitation+5
8 months ago
Autopwn preview

Autopwn

GitHubrpranshu/autopwn

A simple bash based metasploit automation tool!

educationexploit-frameworkspayload-generation+2
1266 years ago
Kage preview
Archived

Kage

GitHubzerx0r/kage

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

command-and-controleducationexploit-frameworks+9
1.2k3 years ago
DuplexSpyCS preview

DuplexSpyCS

GitHubiss4cf0ng/duplexspycs

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

command-and-controleducationpayload-development+5
2226 months ago
Apache-HTTP-Server-2.4.50-RCE preview

Apache-HTTP-Server-2.4.50-RCE

GitHubzyx2440/apache-http-server-2.4.50-rce

Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for…

educationexploitationpenetration-testing+3
22 years ago
CVE-2025-58434-AND-59528-POC preview

CVE-2025-58434-AND-59528-POC

GitHubkartik2005221/cve-2025-58434-and-59528-poc

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

authenticationeducationexploitation+5
184 months ago
CVE-2024-28397-Exploit-Automation preview

CVE-2024-28397-Exploit-Automation

GitHubl1337xi/cve-2024-28397-exploit-automation

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

ctfeducationexploitation+3
29 months ago
Previous12Next