Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
483 results
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

command-and-controlexploitationpayload-development+3
13 days ago
Brute-Ratel-C4-Community-Kit preview

Brute-Ratel-C4-Community-Kit

GitHubparanoidninja/brute-ratel-c4-community-kit

Community payload loaders, scripts, and configurations for Brute Ratel C4, supporting red team command-and-control operations and payload deployment.

command-and-controlexploitationpayload-development+3
3012 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubsandimfz/cve-2024-23692

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

command-and-controlexploitationpayload-generation+2
17 days ago
Heroinn preview

Heroinn

GitHubb23r0/heroinn

A cross platform C2/post-exploitation framework.

command-and-controlpayload-developmentpenetration-testing-frameworks+4
7103 years ago
ImgBackdoor preview

ImgBackdoor

GitHubtsuyoken/imgbackdoor

Builds a trojanized .jpg.exe agent that downloads and executes a user-supplied PowerShell, Batch, or Metasploit payload, then opens a Meterpreter…

command-and-controlexploitationpayload-development+3
3944 years ago
Elevate-System-Trusted-BOF preview

Elevate-System-Trusted-BOF

GitHubmr-un1k0d3r/elevate-system-trusted-bof

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

command-and-controlpayload-developmentpost-exploitation+2
1813 years ago
PoC-Malware-TTPs preview

PoC-Malware-TTPs

GitHubknight0x07/poc-malware-ttps

Curated proof-of-concept implementations of malware TTPs, covering persistence, privilege escalation, command-and-control, and post-exploitation for…

adversarial-attackcommand-and-controlpayload-development+4
483 years ago
freeMetsrvLoader preview

freeMetsrvLoader

GitHubattl4s/freemetsrvloader

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

command-and-controlpayload-developmentpost-exploitation+1
353 years ago
Mystikal preview

Mystikal

GitHubd00mfist/mystikal

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

adversarial-attackcommand-and-controlpayload-development+4
3262 years ago
CS_COFFLoader preview

CS_COFFLoader

GitHubtrustedsec/cs_coffloader
command-and-controlpayload-developmentpenetration-testing+2
1372 years ago
REC2 preview

REC2

GitHubg0h4n/rec2

External C2 framework in Rust that executes commands on Linux, macOS, and Windows implants through VirusTotal and Mastodon APIs with AES-encrypted…

command-and-controlpayload-developmentpenetration-testing+3
1612 years ago
Sub7 preview

Sub7

GitLabillwill/sub7

Legacy Windows RAT source code with client/server backdoor architecture, configurable payload builder, and full remote control for malware research.

command-and-controlmalware-analysispayload-generation+2
152 years ago
backdoors preview

backdoors

GitHubhackerhouse-opensource/backdoors

Tools for maintaining access to systems and proof-of-concept demonstrations.

command-and-controlpayload-developmentpersistence-mechanisms+3
1826 months ago
BloodfangC2 preview

BloodfangC2

GitHubzarkones/bloodfangc2

Modern PIC implant for Windows (64 & 32 bit)

adversarial-attackcommand-and-controlpayload-development+4
1051 year ago
rustbof preview

rustbof

GitHubjoaoviictorti/rustbof

A Rust template for writing Beacon Object Files (BOFs)

command-and-controlpayload-developmentpost-exploitation+1
1316 months ago
Crystal-Loaders preview

Crystal-Loaders

GitHubrasta-mouse/crystal-loaders

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

command-and-controlids-ips-evasionpayload-development+3
2414 months ago
Jasmin-Ransomware preview

Jasmin-Ransomware

GitHubcodesiddhant/jasmin-ransomware

Red team ransomware simulator with custom payload generation, centralized C2 dashboard, and file encryption/decryption for penetration testing.

command-and-controlencryption-decryption-toolsexploitation+5
2875 years ago
Monitor preview

Monitor

GitHubal1ex/monitor

Windows persistence technique using AddMonitor to load a malicious DLL with SYSTEM privileges, enabling remote C2 via Meterpreter.

command-and-controlexploitationpayload-generation+4
535 years ago
Previous12…27Next