Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PyExfil — PyExfil — Python 3 toolkit for researching and stress-testing data exfiltration techniques across network, physical, and steganographic channels. For red team simulation and DLP detection testing. | Kitploit
Tools/GitHubGitHub/ytisf/pyexfil
Data ExfiltrationNetwork SecuritySteganographyRed Teaming
GitHubytisf/pyexfil

PyExfil

PyExfil — Python 3 toolkit for researching and stress-testing data exfiltration techniques across network, physical, and steganographic channels. For red team simulation and DLP detection testing.

View Repository
8081451133 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

PyExfil

Stress Testing Detection & Creativity

Contributions Welcome HitCount PyPI download month PyPI license GitHub stars made-with-python

Logo

PyExfil was born as a PoC and kind of a playground and grew to be something a bit more. In my eyes it's still a messy PoC that needs a lot more work and testing to become stable. The purpose of PyExfil is to set as many exfiltration, and now also communication, techniques that CAN be used by various threat actors/malware around to bypass various detection and mitigation tools and techniques. You can track changes at the official GitHub page.

Putting it simply, it's meant to be used as a testing tool rather than an actual Red Teaming tool. Although most techniques and methods should be easily ported and compiled to various operating systems, some stable some experimental, the transmission mechanism should be stable on all techniques. Clone it, deploy on a node in your organization and see which systems can catch which techniques.

Getting Started

PIP

For using pip (not necessarily the most updated):

pip install --user PyExfil

Prerequisites

For source:

git clone https://www.github.com/ytisf/PyExfil
cd PyExfil
pip install --user -r requirements.txt

We recommend installing py2exe as well so that you may cross compile various modules to a binary for easier transportation. You can do that with:

pip install py2exe

Installing

Go to the same folder where PyExfil was cloned to and:

pip setup.py --user install

List of Techniques

  • Network
    • DNS query
    • HTTP Cookie
    • ICMP (8)
    • NTP Body
    • BGP Open
    • HTTPS Replace Certificate
    • QUIC - No Certificate
    • Slack Exfiltration
    • POP3 Authentication (as password) - Idea thanks to Itzik Kotler
    • FTP MKDIR - Idea thanks to Itzik Kotler
    • Source IP-based Exfiltration
    • HTTP Response
    • IMAP_Draft
  • Communication
    • NTP Request
    • DropBox LSP (Broadcast or Unicast)
    • DNS over TLS
    • ARP Broadcast
    • JetDirect
    • GQUIC - Google Quick UDP Internet Connections (Client Hello)
    • MDNS Query - Can be used as broadcast.
    • AllJoyn. Name Service Protocol (IoT discovery) Version 0 ISAT.
    • PacketSize. Using size of packet rather than actual data.
    • UDP-Source-Port Using the source port in UDP as a transmission medium.
    • CertExchange Leveraging certificate exchange function for short bursts of communication.
    • DNSQ Leveraging DNS Queries for communication.
    • ICMP_TTL Leveraging the TTL byte for communication. Very short but also stealthy.
  • Physical
    • Audio - No listener.
    • QR Codes
    • WiFi - On Payload
    • 3.5mm Jack
    • UltraSonic
  • Steganography
    • Binary Offset
    • Video Transcript to Dictionary
    • Braille Text Document
    • PNG Transparency
    • ZIPCeption
    • DataMatrix over LSB

For usage per modules have a look at the USAGE file.

Data Generation

Although this tool was initially created as a game and later on turned to be a Red Team oriented tool, at the end of a day a major usage of PyExfil is to test various DLP (Data Leakage Protection) systems as well as detection of intrusion. To make the latter mission simpler we have created a little module to generate fake data with a structure that matches both PII and PCI data sets. These are intended to trigger alerts while being broadcate outside of the network.

Here is how to use it:

from pyexfil.includes import CreateTestData

c = CreateTestData(rows=1000, output_location="/tmp/list.csv")
c.Run()

After this you can use which ever PyExfil module you would like to try and exfiltrate the data set created. This way you can test your detection without risking exfiltrating valuable data.

Contributing

We welcome contributions — from testing and bug fixes to entirely new covert channels.

  • DOCUMENTATION.md — how to write a new module using the class hierarchy, which base class to inherit, and where to register it.
  • ARCHITECTURE.md — the full class hierarchy reference (NetworkModule, CommModule, PhysicalModule, StegaModule) with API details and examples.
Download Tool