Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
TransparentTorProxy preview

TransparentTorProxy

GitHubonyks-os/transparenttorproxy

A Linux CLI utility that transparently routes all system traffic through the Tor network using nftables. It enables rapid IP rotation and easy…

command-and-controldefensive-toolsdns-analysis+6
44
3 days ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

cloud-securitycommand-and-controlencryption-decryption-tools+6
4323 days ago
hackEmbedded preview

hackEmbedded

GitHubdoudoudedi/hackembedded

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

command-and-controlembedded-systems-securityencryption-decryption-tools+8
2062 months ago
fawkes preview

fawkes

GitHubgaloryber/fawkes

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

cloud-securitycommand-and-controlcontainer-escape+7
382 months ago
CVE-2024-31317-Deployer preview

CVE-2024-31317-Deployer

GitHubkalibb/cve-2024-31317-deployer

Automated deployment tool for CVE-2024-31317, a command injection vulnerability in Android 9-13. Includes reverse shell payload, compile script, and…

android-securitybinary-exploitationcommand-and-control+5
8 months ago
FiberBreak preview

FiberBreak

GitHubscumfrog/fiberbreak

React2Shell Exploitation Tool (CVE-2025-55182)

cloud-securitycommand-and-controldata-exfiltration+8
9 months ago
pingback preview

pingback

GitHubcorelight/pingback

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

command-and-controlintrusion-detectionmalware-analysis+2
111 year ago
CVE-2025-32433_Erlang-OTP_PoC preview

CVE-2025-32433_Erlang-OTP_PoC

GitHubabrewer251/cve-2025-32433_erlang-otp_poc

This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers

command-and-controlexploitationnetwork-security+3
11 year ago
CVE-2025-32433_PoC preview

CVE-2025-32433_PoC

GitHubodst-forge/cve-2025-32433_poc

This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers

command-and-controlexploitationnetwork-security+3
1 year ago
GraphStrike preview

GraphStrike

GitHubredsiege/graphstrike

Cobalt Strike HTTPS beaconing over Microsoft Graph API

api-securitycloud-securitycommand-and-control+3
6372 years ago
CVE-2023-36143 preview

CVE-2023-36143

GitHubleonardobg/cve-2023-36143

Proof-of-concept exploit for CVE-2023-36143 demonstrating command injection in Maxprint Maxlink 1200G v3.4.11E via the diagnostic tool web interface.

command-and-controlembedded-systems-securityexploitation+3
3 years ago
azureOutlookC2 preview

azureOutlookC2

GitHubboku7/azureoutlookc2

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

api-securitycloud-securitycommand-and-control+2
5033 years ago
PhoneMonitor preview

PhoneMonitor

GitHubglobalpolicy/phonemonitor

A Remote Administration Tool for Android devices

android-securitycommand-and-controldata-exfiltration+3
2685 years ago
blue-pigeon preview

blue-pigeon

GitHubbluepigeonproject/blue-pigeon

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

android-securitybluetooth-securitycommand-and-control+4
575 years ago
snmp-shell preview

snmp-shell

GitHubmxrch/snmp-shell

Shell Simulation over Net-SNMP with extend functionality

command-and-controlexploitationnetwork-security+3
995 years ago
androrat preview

androrat

GitHubwszf/androrat

androrat

android-securitycommand-and-controldata-exfiltration+6
2.0k6 years ago
AndroidClient preview

AndroidClient

GitHubrev-code/androidclient

Android remote administration client

android-securitycommand-and-controlmobile-security+3
118 years ago
AndroRAT preview

AndroRAT

GitHubthe404hacking/androrat

AndroRAT | Remote Administrator Tool for Android OS Hacking

android-securitycommand-and-controlexploitation+4
1.7k8 years ago
Previous12Next