Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
299 results
raider preview

raider

GitHubowasp/raider

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

api-security-testingauthenticationpenetration-testing+3
101
3 years ago
apache-struts-cve-2017-9805 preview

apache-struts-cve-2017-9805

GitHubrvermeulen/apache-struts-cve-2017-9805

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

code-analysisexploitationpenetration-testing+3
5 years ago
Ruby-On-Rails-Path-Traversal-Vulnerability-CVE-2018-3760- preview

Ruby-On-Rails-Path-Traversal-Vulnerability-CVE-2018-3760-

GitHubcyberharsh/ruby-on-rails-path-traversal-vulnerability-cve-2018-3760-

Docker-based lab demonstrating CVE-2018-3760 path traversal in Ruby on Rails Sprockets, with POC and environment setup for security testing and…

educationexploitationlabs-practice+3
36 years ago
Langflow-cve-2026-33017-exploit preview

Langflow-cve-2026-33017-exploit

GitHubcerberusmrxi/langflow-cve-2026-33017-exploit

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

command-and-controldata-exfiltrationexploitation+8
21 month ago
CVE-2018-11776-FIS preview

CVE-2018-11776-FIS

GitHubsonpt-afk/cve-2018-11776-fis

Exploit for CVE-2018-11776, a remote code execution vulnerability in Apache Struts via OGNL injection. Demonstrates the attack vector and impact for…

educationexploitationpenetration-testing+2
3 years ago
DeliberatelyVulnerableWebApp preview
Archived

DeliberatelyVulnerableWebApp

GitHubtimothyjxhn/deliberatelyvulnerablewebapp

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

educationexploitationlabs-practice+3
1 year ago
Myesve preview

Myesve

GitHubnyakki-labs-0x420/myesve

CVE-2024-38475 exploitation & scanning tool with Mullvad VPN rotation

exploitationinformation-gatheringpenetration-testing+5
3 months ago
taowu-cobalt_strike preview

taowu-cobalt_strike

GitHubpandasec888/taowu-cobalt_strike

Red team automation framework built on Cobalt Strike, integrating exploit modules, post-exploitation tools, and lateral movement capabilities for…

command-and-controlexploit-frameworkslateral-movement+7
1.8k9 months ago
phpsploit preview

phpsploit

GitHubnil0x42/phpsploit

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

command-and-controlexploit-frameworkspayload-development+6
2.5k2 years ago
pysqli preview

pysqli

GitHubsysdream/pysqli

Python SQL injection framework

database-securityexploit-frameworkspenetration-testing+3
13213 years ago
joro preview

joro

GitHubbishopfox/joro

A collaborative web exploitation framework.

command-and-controlexploit-frameworksfuzzing+5
443 days ago
nGixshell preview

nGixshell

GitHubmateusverass/ngixshell

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

command-and-controlexploit-frameworkspayload-development+8
254 months ago
novahot preview
Archived

novahot

GitHubchrisallenlane/novahot

A webshell framework for penetration testers.

command-and-controlexploit-frameworkspayload-generation+3
2991 year ago
K8tools preview

K8tools

GitHubk8gege/k8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

command-and-controlexploit-frameworkslateral-movement+9
6.2k1 year ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
3.9k3 months ago
React2Shell-CVE-2025-55182-original-poc preview

React2Shell-CVE-2025-55182-original-poc

GitHublachlan2k/react2shell-cve-2025-55182-original-poc

Original proof-of-concept exploits for React2Shell (CVE-2025-55182), demonstrating remote code execution in Next.js applications via Webpack chunk…

code-analysisexploit-frameworkspayload-development+3
1.1k9 months ago
pystinger preview

pystinger

GitHubfunnywolf/pystinger

Bypass firewall for traffic forwarding using webshell

command-and-controlexploit-frameworksids-ips-evasion+5
1.4k4 years ago
CobaltStrike-Toolset preview

CobaltStrike-Toolset

GitHubqax-a-team/cobaltstrike-toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

command-and-controlexploit-frameworkslateral-movement+8
5937 years ago
Previous1…91011…17Next