Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

Payload 开发

自定义 payload 制作、混淆、AV 规避和交付机制工具。

最新相关性最受欢迎最近更新
3295 结果
内容在请求的语言中不可用。显示英文版本。
CVE-2026-64638-PoC-XSS2Shell- preview

CVE-2026-64638-PoC-XSS2Shell-

GitHubboreas37/cve-2026-64638-poc-xss2shell-

XSS2Shell (CVE-2026-64638) WordPress 未认证 XSS 到 RCE 攻击链 — PoC 漏洞利用 + 防御审计工具 + nuclei 模板

defensive-toolsweb-vulnerability-scannersvulnerability-analysis+6
16
11天前
CVE-2025-59528-PoC preview

CVE-2025-59528-PoC

GitHubloaxert/cve-2025-59528-poc

针对 CVE-2025-59528 的 PoC,用于在 HTB 的 Silentium 机器上实现远程代码执行。

exploitationweb-application-exploitationapi-security-testing+3
11天前
Java-Shellcode-Loader preview

Java-Shellcode-Loader

GitHubyzddmr6/java-shellcode-loader

基于Java实现的Shellcode加载器

shellcodepenetration-testingred-teaming+1
4142年前
CVE-2026-68771_exploit preview

CVE-2026-68771_exploit

GitHub0xdak/cve-2026-68771_exploit

针对 CVE-2026-68771 的未认证利用,该漏洞是 ComfyUI 中的 pickle 反序列化远程代码执行(RCE)漏洞。通过 /upload/image 植入精心构造的 shard,再经 /prompt 触发,可执行命令或开启反弹 Shell。

vulnerability-analysisexploitationweb-application-exploitation+3
117天前
Spring4Shell-POC preview

Spring4Shell-POC

GitHubprinceh4k/spring4shell-poc

用于在隔离环境中利用 CVE-2022-22965 (Spring4Shell) 漏洞的概念验证,并演示了远程代码执行 (RCE)。

vulnerability-analysisexploitationweb-application-exploitation+4
17天前
Nim_DInvoke preview

Nim_DInvoke

GitHubs3cur3th1ssh1t/nim_dinvoke

D/Invoke implementation in Nim

post-exploitationred-teamingpayload-development+1
1014年前
PayloadAutomation preview

PayloadAutomation

GitHubemcghee/payloadautomation

通过 Python 到 Sleep 的桥接,自动化 Cobalt Strike 载荷开发、测试和部署;包括工件检查、IoC 追踪和编译。

ioc-managementpayload-generationscripting-automation+3
1204年前
wptsextensions.dll preview

wptsextensions.dll

GitHubphackt/wptsextensions.dll

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

privilege-escalationpersistence-mechanismsexploitation+3
575年前
SliverKeylogger preview

SliverKeylogger

GitHubtrustedsec/sliverkeylogger

用于 Sliver C2 植入框架的 Windows 键盘记录模块,使用 Raw Input 捕获按键,并向操作员提供启动、停止和检索命令。

data-exfiltrationpost-exploitationcommand-and-control+2
1692年前
PSSW100AVB preview

PSSW100AVB

GitHubtihanyin/pssw100avb

一系列有用的 PowerShell 脚本,100% 免杀(在发布时)。

ids-ips-evasionpost-exploitationpenetration-testing+5
1.4k2个月前
Brute-Ratel-C4-Community-Kit preview

Brute-Ratel-C4-Community-Kit

GitHubparanoidninja/brute-ratel-c4-community-kit

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

exploitationpost-exploitationpenetration-testing+3
2982年前
CdpSvcLPE preview

CdpSvcLPE

GitHubsailay1996/cdpsvclpe

通过 CdpSvc 服务实现 Windows 本地权限提升(可写 SYSTEM 路径 DLL 劫持)

privilege-escalationpersistence-mechanismsexploitation+3
2563年前
SleepyCrypt preview

SleepyCrypt

GitHubsolomonsklash/sleepycrypt

一个在进程休眠时加密运行中进程映像的 shellcode 函数。

ids-ips-evasionshellcodered-teaming+1
3384年前
Empire preview

Empire

GitHubbc-security/empire

适用于红队的加密 C2 与后渗透框架,配备模块化 PowerShell/Python/C#/Go 代理、众多攻击性模块,以及简洁的服务器-客户端架构。

penetration-testing-frameworkspayload-generationids-ips-evasion+5
5.2k19天前
Anti-Virus-Evading-Payloads preview

Anti-Virus-Evading-Payloads

GitHubrosesecurity/anti-virus-evading-payloads

在渗透测试或道德黑客行动的漏洞利用阶段,你最终需要尝试让代码在目标系统计算机上运行。这里有一种在创建后门时规避杀毒软件的简单方法!

payload-generationexploitationpenetration-testing+4
75028天前
nasm_linux_x86_64_pure_sharedlib preview

nasm_linux_x86_64_pure_sharedlib

GitHubtherealdreg/nasm_linux_x86_64_pure_sharedlib

NASM Linux x86_64 纯(无依赖)共享库 (.so),反射式 ELF SO 注入的 POC

exploitationshellcodepost-exploitation+2
323年前
Lockbit-Black-3.0 preview

Lockbit-Black-3.0

GitHubwhichbuffer/lockbit-black-3.0

勒索软件源代码工件,用于分析加密例程、载荷机制,以及构建检测和事件响应对策。

encryption-decryption-toolsmalware-analysispayload-development
274年前
PINKPANTHER preview

PINKPANTHER

GitHubwinterknife/pinkpanther

Windows x64 手工制作的令牌窃取内核模式 shellcode

privilege-escalationshellcodepost-exploitation+2
5172年前
上一页1…345…184下一页