Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
299 results
cloudrasp-log4j2 preview

cloudrasp-log4j2

GitHubboundaryx/cloudrasp-log4j2

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

defensive-toolsexploit-frameworksvulnerability-analysis+1
126
4 years ago
CVE-2022-39197-POC preview

CVE-2022-39197-POC

GitHubxzajyjs/cve-2022-39197-poc

CVE-2022-39197(CobaltStrike XSS <=4.7) POC

command-and-controlexploit-frameworkspenetration-testing+3
463 years ago
CVE-2022-40684-metasploit-scanner preview

CVE-2022-40684-metasploit-scanner

GitHubtaroballzchen/cve-2022-40684-metasploit-scanner

An authentication bypass using an alternate path or channel in Fortinet product

authenticationexploitationexploit-frameworks+3
143 years ago
CVE-2018-3252 preview

CVE-2018-3252

GitHubgo-spider/cve-2018-3252

Exploit for CVE-2018-3252 targeting WebLogic deserialization vulnerability. Includes payload generation with ysoserial and a Python proof-of-concept…

binary-exploitationexploit-frameworkspayload-development+3
187 years ago
wp2shell-poc2 preview

wp2shell-poc2

GitHubattackercan/wp2shell-poc2

CVE-2026-63030

command-and-controlexploit-frameworkspayload-development+5
71 month ago
cobaltstrike_swing_xss2rce preview

cobaltstrike_swing_xss2rce

GitHubhluwa/cobaltstrike_swing_xss2rce

Exploit for CVE-2022-39197, a cross-site scripting vulnerability in Cobalt Strike's Swing GUI that enables remote code execution on team servers.

command-and-controlexploit-frameworkspenetration-testing+3
73 years ago
CVE-2019-3929 preview

CVE-2019-3929

GitHubxfox64x/cve-2019-3929

Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module

command-and-controlexploit-frameworkspenetration-testing+3
56 years ago
React2Shell preview

React2Shell

GitHubkhadafigans/react2shell

React2Shell - CVE-2025-66478 RCE Exploit

command-and-controlexploit-frameworkspayload-development+3
67 months ago
CVE-2024-38472 preview

CVE-2024-38472

GitHubabdurahmon3236/cve-2024-38472

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

command-and-controlexploit-frameworkslateral-movement+6
42 years ago
TerraMaster-TOS-CVE-2020-15568 preview

TerraMaster-TOS-CVE-2020-15568

GitHubdivinepwner/terramaster-tos-cve-2020-15568

Repository for CVE-2020-15568 Metasploit module

command-and-controlexploit-frameworkspenetration-testing+3
33 years ago
WordPress_Backup_Migration-RCE_Unauthenticated preview

WordPress_Backup_Migration-RCE_Unauthenticated

GitHubjoaoaugustom/wordpress_backup_migration-rce_unauthenticated

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

command-and-controlexploit-frameworkspayload-development+3
1 month ago
CVE-2023-46818 preview

CVE-2023-46818

GitHubsyfi/cve-2023-46818

Metasploit Modules

code-analysisexploit-frameworkspayload-development+3
1 year ago
-CVE-2024-31211 preview

-CVE-2024-31211

GitHubabdurahmon3236/-cve-2024-31211

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

code-analysisexploit-frameworkspayload-development+3
2 years ago
CVE-2024-6366 preview

CVE-2024-6366

GitHubabdurahmon3236/cve-2024-6366

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

code-analysisexploit-frameworkspayload-development+3
2 years ago
APOLOGEE preview
Archived

APOLOGEE

GitHubrosesecurity/apologee

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

authenticationexploitationexploit-frameworks+8
501 year ago
beef preview

beef

GitHubbeefproject/beef

The Browser Exploitation Framework Project

command-and-controlexploitationexploit-frameworks+8
11.0k20h 39m ago
katana preview

katana

GitHubprojectdiscovery/katana

A next-generation crawling and spidering framework.

api-securityapi-security-testingcrawler+7
17.5k3 days ago
TokenFlare preview

TokenFlare

GitHubjumpseclabs/tokenflare

Serverless AITM Simulation Framework for Entra ID and M365

authenticationcloud-securitycommand-and-control+6
2438 months ago
Previous1…101112…17Next