Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
14 days ago
BOF_Collection preview

BOF_Collection

GitHubrvrsh3ll/bof_collection

Cobalt Strike BOFs for in-memory post-exploitation: Active Directory enumeration, clipboard capture, WiFi credential dump, port scan, and registry…

command-and-controlinformation-gatheringpersistence-mechanisms+4
7853 years ago
PPEnum preview

PPEnum

GitHubrasta-mouse/ppenum

Simple BOF to read the protection level of a process

command-and-controlinformation-gatheringpenetration-testing+2
1233 years ago
nopowershell preview

nopowershell

GitHubbitsadmin/nopowershell

PowerShell rebuilt in C# for Red Teaming purposes

command-and-controlinformation-gatheringpost-exploitation+2
1.1k5 months ago
mqxss preview

mqxss

GitHubgrampae/mqxss

Hooked browser communication over MQTT

command-and-controlinformation-gatheringpayload-generation+4
82 years ago
SteppingStones preview

SteppingStones

GitHubnccgroup/steppingstones

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

command-and-controlinformation-gatheringpenetration-testing+3
2434 days ago
nimrm preview

nimrm

GitHubblue0x1/nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

authenticationcommand-and-controlinformation-gathering+6
51 month ago
f5-bigip-rce-cve-2020-5902 preview

f5-bigip-rce-cve-2020-5902

GitHubthelsa/f5-bigip-rce-cve-2020-5902

Automated CVE-2020-5902 detection and exploitation tool for F5 BIG-IP TMUI, supporting single/batch vulnerability checks, file read/write, user…

command-and-controlexploitationinformation-gathering+3
626 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubytxzx/cve-2022-26134

Python-based exploit for CVE-2022-26134, an OGNL injection vulnerability in Confluence Server and Data Center. Supports single URL check and batch…

command-and-controlexploitationinformation-gathering+3
2 years ago
CVE-2017-10271 preview

CVE-2017-10271

GitHubluffin/cve-2017-10271

Python script to detect CVE-2017-10271 (Weblogic wls-wsat deserialization RCE) using out-of-band DNS log verification via ceye.io. Supports Windows…

command-and-controlexploitationreconnaissance+2
298 years ago
LSTAR preview

LSTAR

GitHublintstar/lstar

Comprehensive CobaltStrike post-exploitation plugin integrating modules for privilege escalation, lateral movement, credential dumping, persistence,…

command-and-controlexploitationinformation-gathering+7
1.3k4 years ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Exploit for CVE-2026-58057 targeting Flowise Windows RCE via case-sensitive environment variable validation bypass. Supports reverse shell,…

command-and-controlexploitationinformation-gathering+7
11 month ago
PhaseHack preview

PhaseHack

GitHubmalwaretech/phasehack

Blind SQL injection tool to extract login credentials from Phase botnet command-and-control servers via automated injection payloads.

command-and-controlinformation-gatheringvulnerability-analysis+1
911 years ago
Xenotix-xBOT preview

Xenotix-xBOT

GitHubajinabraham/xenotix-xbot

Cross-platform proof-of-concept botnet that abuses Google Services (Forms, Spreadsheets, Data API) for encrypted C2 communication, enabling remote…

command-and-controlexploitationinformation-gathering+4
288 years ago
bothan preview

bothan

GitHubaudibleblink/bothan

CLI tool to confirm if an IP:port hosts an Empire C2 server, with support for masscan output parsing and batch scanning from file or stdin.

command-and-controldefensive-toolsinformation-gathering+3
276 years ago
quasibot preview

quasibot

GitHubsmaash/quasibot

complex webshell manager, quasi-http botnet.

command-and-controlexploitationinformation-gathering+6
28411 years ago
XeytanWxCpp-RAT preview

XeytanWxCpp-RAT

GitHubmelardev/xeytanwxcpp-rat

Work in Progress. RAT written in C++ using wxWidgets

command-and-controlinformation-gatheringpayload-development+3
116 years ago
Hale preview

Hale

GitHubpjlantz/hale

Modular botnet command & control monitor with IRC/HTTP protocol support, SOCKS proxy anonymization, XMPP sensor coordination, and RESTful API for…

command-and-controlincident-responseinformation-gathering+5
2024 years ago
Previous12345Next