Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17584 results
KittyStager preview

KittyStager

GitHubenelg52/kittystager

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

command-and-controleducationencryption-decryption-tools+6
228
3 years ago
GraphStrike preview

GraphStrike

GitHubredsiege/graphstrike

Cobalt Strike HTTPS beaconing over Microsoft Graph API

api-securitycloud-securitycommand-and-control+3
6382 years ago
DoHC2 preview
Archived

DoHC2

GitHubspiderlabs/dohc2

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

command-and-controldns-analysisexploit-frameworks+3
4506 years ago
BruteLoops preview

BruteLoops

GitHubimpostorkeanu/bruteloops

Protocol agnostic online password guessing API.

authenticationpassword-attackspenetration-testing+1
853 years ago
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
3003 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubmr-r00t11/cve-2024-23692

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

exploitationpayload-generationpenetration-testing+4
2 years ago
SimpleRmiDiscoverer preview

SimpleRmiDiscoverer

GitHubmarcin-wolak/simplermidiscoverer

Simple JMX RMI scanning tool

api-security-testinginformation-gatheringmisconfiguration+2
42 years ago
Cuteit preview

Cuteit

GitHubd4vinci/cuteit

IP obfuscator made to make a malicious ip a bit cuter

command-and-controlids-ips-evasionpayload-generation+4
5471 year ago
paragon preview

paragon

GitHubkcarretto/paragon

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

command-and-controlexploit-frameworkspayload-development+4
3042 years ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
3.9k3 months ago
CVE-2022-39197 preview

CVE-2022-39197

GitHubits-arun/cve-2022-39197

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

command-and-controlexploitationpayload-development+3
3873 years ago
SMShell preview

SMShell

GitHubpersistent-security/smshell

PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers

command-and-controlexploitationmobile-security+3
3723 years ago
CVE-2022-27925-PoC preview

CVE-2022-27925-PoC

GitHubvnhacker1337/cve-2022-27925-poc

Zimbra RCE simple poc

exploitationpenetration-testingred-teaming+2
654 years ago
zoshrinkC2 preview

zoshrinkC2

GitHubdemon-i386/zoshrinkc2

DNS over HTTPS targeted malware (only runs once)

command-and-controlcryptographyids-ips-evasion+3
973 years ago
S2-053-CVE-2017-12611 preview

S2-053-CVE-2017-12611

GitHubbrianwrf/s2-053-cve-2017-12611

A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)

command-and-controlexploitationpayload-generation+3
379 years ago
malvinci preview

malvinci

GitHubgsoffmarket/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controldata-exfiltrationpayload-development+3
592 years ago
c2s preview

c2s

GitHubj3ssie/c2s

Command and Control server on Slack

command-and-controlpenetration-testingpost-exploitation+2
307 years ago
wshlient preview

wshlient

GitHubgildasio/wshlient

A simple tool to interact with web shells and command injection vulnerabilities

command-and-controlpenetration-testingshellcode+1
371 year ago
Previous12…100Next