Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
OffensiveCpp preview

OffensiveCpp

GitHublsecqt/offensivecpp

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

adversarial-attackcurated-resourcesexploitation+6
7741 year ago
msf_shellcode_analysis preview

msf_shellcode_analysis

GitHubyo-yo-yo-jbo/msf_shellcode_analysis

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

binary-analysiseducationmalware-analysis+3
282 months ago
AsmLdr preview

AsmLdr

GitHub0xninjacyclone/asmldr

Dynamic shellcode loader with sophisticated evasion capabilities

ids-ips-evasionpayload-developmentpayload-generation+3
3441 year ago
React-Server-Components-RCE preview

React-Server-Components-RCE

GitHubgelukcrab/react-server-components-rce

React Server Components 远程代码执行漏洞(CVE-2025-55182)

command-and-controlctfeducation+8
910 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubfaithtiannn/cve-2025-55182

CVE-2025-55182漏洞检测工具

command-and-controlexploitationpayload-development+5
28 months ago
CVE-2025-34085 preview

CVE-2025-34085

GitHubyukinime/cve-2025-34085

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

exploitationpayload-generationpenetration-testing+3
71 year ago
htshells preview

htshells

GitHubwireghoul/htshells

Self contained htaccess shells and attacks

exploitationinformation-gatheringpayload-generation+5
1.1k4 years ago
NyxInvoke preview

NyxInvoke

GitHubblacksnufkin/nyxinvoke

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

command-and-controlexploitationids-ips-evasion+6
2431 year ago
quasibot preview

quasibot

GitHubsmaash/quasibot

complex webshell manager, quasi-http botnet.

command-and-controlexploitationinformation-gathering+6
28411 years ago
OffensiveDLR preview

OffensiveDLR

GitHubbyt3bl33d3r/offensivedlr

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

code-analysiscommand-and-controldynamic-code-analysis+9
5255 years ago
CVE-2024-35106-POC preview

CVE-2024-35106-POC

GitHublaskdjlaskdj12/cve-2024-35106-poc

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

binary-exploitationembedded-systems-securityexploitation+5
1 year ago
CVE-2024-29671-POC preview

CVE-2024-29671-POC

GitHublaskdjlaskdj12/cve-2024-29671-poc

This is POC of CVE-2024-29671

binary-exploitationembedded-systems-securityexploitation+7
11 year ago
CVE-2024-51793 preview

CVE-2024-51793

GitHubktn1990/cve-2024-51793

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

code-analysisexploitationpayload-generation+6
19 months ago
POC-CVE-2021-42013-EXPLOIT preview

POC-CVE-2021-42013-EXPLOIT

GitHubmakavellik/poc-cve-2021-42013-exploit

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

command-and-controlexploitationinformation-gathering+7
1 year ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubjenderal92/cve-2026-48908

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell…

exploitationpayload-generationpenetration-testing+4
33 months ago
CVE-2025-52691-poc preview

CVE-2025-52691-poc

GitHubrimbadirgantara/cve-2025-52691-poc

Proof-of-concept exploit for CVE-2025-52691: unauthenticated arbitrary file upload leading to RCE in SmarterMail. Includes vulnerability scanner,…

educationexploitationpayload-generation+5
39 months ago
CVE-2025-2620-poc preview

CVE-2025-2620-poc

GitHubotsmane-ahmed/cve-2025-2620-poc

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

binary-exploitationembedded-systems-securityexploitation+8
161 year ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubluoqichen/cve-2025-55182-poc

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

command-and-controlexploitationpayload-development+5
7 months ago
Previous123Next