Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
239 results
py-log4shellscanner preview

py-log4shellscanner

GitHubscheibling/py-log4shellscanner

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

dns-analysisexploitationfuzzing+3
4 years ago
CVE-2017-5487 preview

CVE-2017-5487

GitHubndr-repo/cve-2017-5487

PoC for CVE-2017-5487 - WordPress User Enumeration via REST

information-gatheringpenetration-testingred-teaming+3
1 year ago
CVE-2025-41373 preview
Archived

CVE-2025-41373

GitHubbytereaper77/cve-2025-41373

PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1

exploitationpenetration-testingvulnerability-analysis+2
21 year ago
Freeze preview
Archived

Freeze

GitHuboptiv/freeze

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

exploit-frameworksids-ips-evasionpayload-development+8
1.5k3 years ago
naxsi preview
Archived

naxsi

GitHubnbs-system/naxsi

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

api-securityids-ips-evasionvulnerability-scanners+3
4.8k2 years ago
ftw preview
Archived

ftw

GitHubfastly/ftw

Framework for Testing WAFs (FTW!)

devsecopspenetration-testingvulnerability-scanners+2
2633 years ago
Advanced-SQL-Injection-Cheatsheet preview

Advanced-SQL-Injection-Cheatsheet

GitHubkleiton0x00/advanced-sql-injection-cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

curated-resourceseducationpenetration-testing+4
3.2k3 years ago
quickjack preview

quickjack

GitHubsamyk/quickjack

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

educationexploitationids-ips-evasion+4
24711 years ago
Nextjs_RCE_Exploit_Tool preview

Nextjs_RCE_Exploit_Tool

GitHubpyroxenites/nextjs_rce_exploit_tool

Exploit for CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+6
1428 months ago
React2Shell preview

React2Shell

GitHubblacktechx011/react2shell

React2Shell: An exploitation framework for CVE-2025-55182 (Next.js/React RCE).

educationexploit-frameworkspayload-development+5
118 months ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
web-application-firewall- preview

web-application-firewall-

GitHubnithylesh/web-application-firewall-

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

educationexploitationids-ips-evasion+5
32 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubceh-aditya-raj/cve-2025-55182

Proof-of-concept research tool for CVE-2025-55182, a critical unauthenticated RCE in Next.js App Router caused by server-side object injection in…

educationexploitationpayload-development+5
28 months ago
CVE-2025-55182-React-RSC-Exploit preview

CVE-2025-55182-React-RSC-Exploit

GitHublutraat/cve-2025-55182-react-rsc-exploit

Basic Proof of Concept (Poc) Exploit for React RSC - CVE-2025-55182

educationexploitationpayload-development+3
5 months ago
PHP-REVERSE-SHELL preview

PHP-REVERSE-SHELL

GitLabs_r_e_e_r_a_j/php-reverse-shell

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

command-and-controleducationids-ips-evasion+6
111 months ago
NSE_CVE-2025-55182 preview

NSE_CVE-2025-55182

GitHubjahaziellem/nse_cve-2025-55182

Nmap NSE script for scanning React2Shell (CVE-2025-55182)

educationexploitationpayload-generation+5
18 months ago
TPASLog4ShellPoC preview
Archived

TPASLog4ShellPoC

GitHubcarlos-mesquita/tpaslog4shellpoc

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

educationexploitationpayload-generation+3
11 year ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerfuzzinginformation-gathering+6
15.1k1 year ago
Previous1…456…14Next