Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
CVE-2024-22120-RCE preview

CVE-2024-22120-RCE

GitHubw01fh4cker/cve-2024-22120-rce

Time Based SQL Injection in Zabbix Server Audit Log --> RCE

exploitationpenetration-testingred-teaming+2
139
2 years ago
CVE-2023-46747-RCE preview

CVE-2023-46747-RCE

GitHubw01fh4cker/cve-2023-46747-rce

Exploit for CVE-2023-46747, a remote code execution vulnerability in F5 BIG-IP, allowing unauthorized user creation and command execution.

authenticationexploitationpenetration-testing+3
2061 year ago
CVE-2022-23808 preview

CVE-2022-23808

GitHubdipakpanchal05/cve-2022-23808

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

exploitationpenetration-testingred-teaming+3
1151 year ago
pwnfaces preview

pwnfaces

GitHubdsssssssm/pwnfaces

exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support

exploitationpenetration-testingred-teaming+2
193 years ago
opmonster preview

opmonster

GitHubphor3nsic/opmonster

CVE-2020-8636 authenticated remote code execution exploit for Opmon

exploitationpenetration-testingred-teaming+3
22 months ago
CVE-2025-70886 preview
Archived

CVE-2025-70886

GitHubhowiehz/cve-2025-70886

A Proof of Concept (PoC) exploit for CVE-2025-70886, a persistent denial-of-service vulnerability in Halo CMS (v2.22.4 and earlier) that allows…

exploitationpenetration-testingred-teaming+2
7 months ago
Kraken preview

Kraken

GitHubkraken-ng/kraken

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

command-and-controlpayload-generationred-teaming+1
5562 years ago
HTMLSmuggler preview

HTMLSmuggler

GitHubd00movenok/htmlsmuggler

✉️ HTML Smuggling generator&obfuscator for your Red Team operations

ids-ips-evasionpayload-generationphishing+2
2012 years ago
phantomrecon preview

phantomrecon

GitHubl33tdawg/phantomrecon

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

dns-analysisexploitationinformation-gathering+6
37 months ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5344 years ago
T3MP3ST preview

T3MP3ST

GitHubelder-plinius/t3mp3st

autonomous red teaming platform; multi-agent offensive-security meta-harness

ai-securitybinary-analysiscloud-security+9
6.1k5 days ago
malicious-pdf preview

malicious-pdf

GitHubjonaslejon/malicious-pdf

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

data-exfiltrationeducationexploitation+6
4.3k17 days ago
dns-rebind-toolkit preview

dns-rebind-toolkit

GitHubbrannondorsey/dns-rebind-toolkit

A front-end JavaScript toolkit for creating DNS rebinding attacks.

dns-analysiseducationexploitation+6
5034 years ago
adversary_emulation_library preview

adversary_emulation_library

GitHubcenter-for-threat-informed-defense/adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

curated-resourcesdata-exfiltrationdefensive-tools+5
2.2k1 year ago
CVE-2024-21683-RCE preview

CVE-2024-21683-RCE

GitHubw01fh4cker/cve-2024-21683-rce

CVE-2024-21683 Confluence Post Auth RCE

exploitationpayload-generationpenetration-testing+3
1272 years ago
CVE-2023-47246-EXP preview

CVE-2023-47246-EXP

GitHubw01fh4cker/cve-2023-47246-exp

exploit for cve-2023-47246 SysAid RCE (shell upload)

exploitationpayload-generationpenetration-testing+3
512 years ago
CVE-2020-0688-GUI preview

CVE-2020-0688-GUI

GitHubw01fh4cker/cve-2020-0688-gui

GUI Exploit Tool for CVE-2020-0688(Microsoft Exchange default MachineKeySection deserialize vulnerability)

exploitationpayload-generationred-teaming+3
162 years ago
CVE-2025-20029-simulation preview

CVE-2025-20029-simulation

GitHubschoi1337/cve-2025-20029-simulation

Simulated environment for CVE-2025-20029 using Docker. Includes PoC and auto-reporting.

command-and-controleducationlabs-practice+3
31 year ago
Previous1234Next