Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
454 results
ASPX_WebShell_COFFLoader preview

ASPX_WebShell_COFFLoader

GitHubepotseluevskaya/aspx_webshell_coffloader

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

command-and-controlpayload-developmentpenetration-testing+3
136
6 months ago
nano preview

nano

GitHubs0md3v/nano

Nano is a family of PHP web shells which are code golfed for stealth.

command-and-controlpayload-generationpenetration-testing+3
4496 years ago
CVE-2018-8941 preview

CVE-2018-8941

GitHubsecforce/cve-2018-8941

D-Link DSL-3782 Code Execution (Proof of Concept)

binary-exploitationembedded-systems-securityexploitation+6
98 years ago
SharpProxyLogon preview

SharpProxyLogon

GitHubflangvik/sharpproxylogon

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

exploitationpayload-developmentpost-exploitation+3
2475 years ago
Flangvik preview

Flangvik

GitHub1342486672/flangvik

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

exploitationpayload-generationpenetration-testing+2
4 years ago
Flangvik preview

Flangvik

GitHubyaoxiaoangry3/flangvik

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

exploitationpenetration-testingshellcode+2
4 years ago
CVE-2025-24893 preview

CVE-2025-24893

GitHubandwati/cve-2025-24893

Python exploit for CVE-2025-24893 that executes a reverse shell on vulnerable web applications, with shell upgrade instructions.

command-and-controlexploitationpayload-generation+3
1 year ago
EXPLOIT-CVE-2026-8832- preview

EXPLOIT-CVE-2026-8832-

GitHubfunixone/exploit-cve-2026-8832-

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

code-analysisexploitationpayload-development+5
4 months ago
spring-core-rce preview

spring-core-rce

GitHubliangyueliangyue/spring-core-rce

Python-based exploit for CVE-2022-22965 (Spring4Shell) with vulnerability detection and webshell injection (Behinder/Godzilla) into Spring web…

exploitationpayload-generationpenetration-testing+3
264 years ago
0-click-RCE-Exploit-for-CVE-2024-50498 preview

0-click-RCE-Exploit-for-CVE-2024-50498

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-50498

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

exploitationpayload-generationpenetration-testing+5
18 months ago
CVE-2024-35106-POC preview

CVE-2024-35106-POC

GitHublaskdjlaskdj12/cve-2024-35106-poc

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

binary-exploitationembedded-systems-securityexploitation+5
1 year ago
CVE-2019-11447_reverse_shell_upload preview

CVE-2019-11447_reverse_shell_upload

GitHubsubsting/cve-2019-11447_reverse_shell_upload

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

exploitationpayload-generationpenetration-testing+3
2 years ago
KittyStager preview

KittyStager

GitHubenelg52/kittystager

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

command-and-controleducationencryption-decryption-tools+6
2263 years ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
39.1k21h 5m ago
ctf-tools preview

ctf-tools

GitHubzardus/ctf-tools

Some setup scripts for security research tools.

binary-analysiscryptographyctf+9
9.5k23 days ago
K8tools preview

K8tools

GitHubk8gege/k8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

command-and-controlexploit-frameworkslateral-movement+9
6.2k1 year ago
gef preview

gef

GitHubhugsy/gef

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

ai-assisted-reversingbinary-analysisbinary-exploitation+10
8.4k1 month ago
reverse-shell-generator preview

reverse-shell-generator

GitHub0dayctf/reverse-shell-generator

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

ctfexploitationpayload-development+6
4.1k5 months ago
Previous1234…26Next