Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

Payload 开发

自定义 payload 制作、混淆、AV 规避和交付机制工具。

最新相关性最受欢迎最近更新
3296 结果
内容在请求的语言中不可用。显示英文版本。
TangledWinExec preview

TangledWinExec

GitHubdaem0nc0re/tangledwinexec

用于研究 Windows 进程执行技术的 PoC 和工具

ids-ips-evasionreverse-engineeringshellcode+6
9586个月前
NiCOFF preview

NiCOFF

GitHubfrkngksl/nicoff

COFF and BOF Loader written in Nim

post-exploitationpenetration-testingred-teaming+1
1774个月前
POC-CVE-2017-8464-OpenCalculator preview

POC-CVE-2017-8464-OpenCalculator

GitHubplayboisk8/poc-cve-2017-8464-opencalculator

利用 .lnk 漏洞以及操作系统对 explorer.exe 和 USB 驱动器的处理机制。

vulnerability-analysisexploitationbinary-analysis+2
12天前
Shellcrypt preview

Shellcrypt

GitHubiilegacyyii/shellcrypt

一款用于混淆 shellcode 的 QoL 工具。未来将支持串联编码/加密/压缩方法。

encryption-decryption-toolspayload-generationshellcode+3
2163年前
CVE-2026-64638 preview

CVE-2026-64638

GitHubdungsocool/cve-2026-64638

CVE-2026-64638 的概念验证漏洞利用:WordPress 登录中的反射型 XSS 与 DOM clobbering 链式利用,可实现管理员账户接管和远程代码执行。

phishing-toolsvulnerability-analysiscode-analysis+4
12天前
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubjendmaoul/xss2shell-cve-2026-64638

CVE-2026-64638 — WordPress 预认证反射型 XSS → 通过 DOM Clobbering 实现 RCE + 应用密码窃取 + REST API 插件激活。双模式 PoC(XSS 链 & 直接)。

exploitationweb-application-exploitationpost-exploitation+4
113天前
log4j-shell-poc preview

log4j-shell-poc

GitHubjiahong-guan/log4j-shell-poc

CVE-2021-44228 漏洞的概念验证。

payload-generationexploitationweb-application-exploitation+3
112天前
Root-My-Galaxy preview

Root-My-Galaxy

GitHubruik-tech/root-my-galaxy

适用于受支持的 Samsung Galaxy 固件的 KSU 安装程序,支持 CVE-2026-43499

android-securityprivilege-escalationexploitation+2
12天前
CVE-2026-63077 preview

CVE-2026-63077

GitHubanggatechi/cve-2026-63077

JetBrains TeamCity 的概念验证漏洞利用程序,通过代理轮询协议反序列化执行未认证远程代码执行,部署 JSP 载荷,并支持多线程命令执行。

exploitationweb-application-exploitationweb-security+2
13天前
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

shellcodepost-exploitationred-teaming+1
5132年前
NoFaxGiven preview

NoFaxGiven

GitHubhackerhouse-opensource/nofaxgiven

NETWORK SERVICE FAX 服务中的代码执行与持久化

privilege-escalationpersistence-mechanismsexploitation+3
376个月前
CVE-2026-64638 preview

CVE-2026-64638

GitHub4minx/cve-2026-64638

针对 WordPress 预认证反射型 XSS(CVE-2026-64638)的单文件 HTML 概念验证,演示了未认证的 JavaScript 执行,并展示了通过 DOM clobbering 和应用密码上传实现的 XSS 到 RCE 利用链。

vulnerability-analysisexploitationweb-application-exploitation+3
113天前
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

vulnerability-scannersexploitationweb-application-exploitation+3
213天前
PowerSploit preview

PowerSploit

GitHubzerodaylab/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

penetration-testing-frameworksprivilege-escalationreconnaissance+7
2394年前
rust_syscalls preview

rust_syscalls

GitHubjanoglezcampos/rust_syscalls

用于 Windows 的单一存根直接与间接系统调用,支持运行时 SSN 解析。

ids-ips-evasionpost-exploitationred-teaming+1
2403年前
Heroinn preview

Heroinn

GitHubb23r0/heroinn

跨平台 C2/后渗透框架。

penetration-testing-frameworkspost-exploitationcommand-and-control+4
7123年前
SharpWhispers preview

SharpWhispers

GitHubsecforce/sharpwhispers

SysWhispers2 的 C# 移植版本。它使用 SharpASM 查找代码洞以执行系统调用存根。

ids-ips-evasionshellcodepost-exploitation+2
1123年前
GwisinMsi preview

GwisinMsi

GitHubchoisg/gwisinmsi

基于 ASEC/AhnLab 博客文章的 PoC MSI payload

malware-analysisred-teamingpayload-development+1
253年前
上一页1…567…184下一页