Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
235 results
postshell preview

postshell

GitHubrek7/postshell

PostShell - Post Exploitation Bind/Backconnect Shell

anti-botcommand-and-controlpayload-generation+5
817 years ago
Lucky-Spark preview

Lucky-Spark

GitHubschich/lucky-spark

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

binary-analysiscommand-and-controlexploitation+6
591 month ago
CVE-2019-0808 preview

CVE-2019-0808

GitHubexodusintel/cve-2019-0808

Win32k Exploit by Grant Willcox

exploitationpayload-generationprivilege-escalation+2
907 years ago
SpringFramework_CVE-2022-22965_RCE preview

SpringFramework_CVE-2022-22965_RCE

GitHubsecnn/springframework_cve-2022-22965_rce

SpringFramework 远程代码执行漏洞CVE-2022-22965

exploitationpayload-generationpenetration-testing+3
724 years ago
CVE-2023-32315-Openfire-Bypass preview

CVE-2023-32315-Openfire-Bypass

GitHubtangxiaofeng7/cve-2023-32315-openfire-bypass

rce

exploitationpayload-generationpenetration-testing+3
1423 years ago
byvalver preview

byvalver

GitHubumpolungfish/byvalver

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

binary-analysisexploitationmachine-learning+6
636 months ago
PichichiH0ll0wer preview

PichichiH0ll0wer

GitHubitaymigdal/pichichih0ll0wer

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

binary-exploitationexploitationpayload-generation+3
651 year ago
CVE-2025-22457 preview

CVE-2025-22457

GitHubsfewer-r7/cve-2025-22457

PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy…

binary-exploitationexploitationpayload-generation+6
731 year ago
WizardOpium preview

WizardOpium

GitHubforrest-orr/wizardopium

Google Chrome Use After Free

binary-exploitationexploitationpayload-generation+2
604 years ago
CVE-2019-17026-Exploit preview

CVE-2019-17026-Exploit

GitHubmaxpl0it/cve-2019-17026-exploit

An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).

binary-exploitationexploitationpayload-generation+2
476 years ago
CVE-2017-13089 preview

CVE-2017-13089

GitHubmzeyong/cve-2017-13089

CVE-2017-13089

exploitationpayload-generationpenetration-testing+2
558 years ago
warsend preview

warsend

GitHubthewhiteh4t/warsend

Apache Tomcat Manager API WAR Shell Upload

exploitationpayload-generationpenetration-testing+3
366 years ago
CVE-2024-45519 preview

CVE-2024-45519

GitHubp33d/cve-2024-45519

SMTP vulnerability scanner and exploit script that checks for CVE-2024-45519 and establishes a reverse shell on vulnerable servers.

exploitationpayload-generationpenetration-testing+3
421 year ago
sc2pe preview

sc2pe

GitHubdump-guy/sc2pe

Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE

payload-developmentpayload-generationshellcode
673 years ago
CVE-2023-41425 preview

CVE-2023-41425

GitHubprodigiousmind/cve-2023-41425

WonderCMS Authenticated RCE - CVE-2023-41425

exploitationpayload-generationphishing+3
271 year ago
Larascript preview

Larascript

GitHubpwnedshell/larascript

Laravel RCE exploit. CVE-2018-15133

exploitationpayload-generationremote-access-tool+3
354 years ago
spring-core-rce preview

spring-core-rce

GitHubliangyueliangyue/spring-core-rce

Python-based exploit for CVE-2022-22965 (Spring4Shell) with vulnerability detection and webshell injection (Behinder/Godzilla) into Spring web…

exploitationpayload-generationpenetration-testing+3
264 years ago
CVE-2025-34085-Multi-target preview

CVE-2025-34085-Multi-target

GitHubill-deed/cve-2025-34085-multi-target

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

command-and-controlexploitationpayload-generation+5
341 year ago
Previous1…678…14Next