Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
253 results
ddoor preview

ddoor

GitHubrek7/ddoor

DDoor - cross platform backdoor using dns txt records

anti-botcommand-and-controldns-analysis+5
304 years ago
XWiki-Platform-RCE-CVE-2025-24893 preview

XWiki-Platform-RCE-CVE-2025-24893

GitHub0xdtc/xwiki-platform-rce-cve-2025-24893

Bash exploit for CVE-2025-24893, unauthenticated RCE in XWiki Platform, using template injection in the SolrSearch macro to execute arbitrary system…

command-and-controlexploitationpayload-development+3
9 months ago
OffensiveNotion preview
Archived

OffensiveNotion

GitHubmttaggart/offensivenotion

Notion as a platform for offensive operations

command-and-controlpayload-developmentpenetration-testing-frameworks+6
1.2k3 years ago
abaddon preview
Archived

abaddon

GitHubwavestone-cdt/abaddon

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

cloud-infrastructure-securitycommand-and-controlexploit-frameworks+5
3313 years ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k8h 13m ago
Covenant preview

Covenant

GitHubcobbr/covenant

Covenant is a collaborative .NET C2 framework for red teamers.

command-and-controlexploit-frameworkspayload-generation+2
4.7k5 years ago
emp3r0r preview

emp3r0r

GitHubjm33-m0/emp3r0r

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

anti-botcommand-and-controlids-ips-evasion+10
1.7k11h 39m ago
SillyRAT preview

SillyRAT

GitHubhash3lizer/sillyrat

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

command-and-controlpayload-generationpost-exploitation+1
9393 years ago
MetasploitMCP preview

MetasploitMCP

GitHubgh05tcrew/metasploitmcp

MCP Server for Metasploit

command-and-controlexploitationexploit-frameworks+8
7236 months ago
kubesploit preview

kubesploit

GitHubcyberark/kubesploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

command-and-controlcontainer-escapecontainer-security+8
1.2k1 year ago
FudgeC2 preview

FudgeC2

GitHubziconius/fudgec2

FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.

command-and-controldata-exfiltrationexploit-frameworks+7
2533 years ago
meteor preview

meteor

GitHubdegenerat3/meteor

A cross-platform C2/teamserver supporting multiple transport protocols, written in Go.

command-and-controlexploit-frameworksnetwork-security+4
453 years ago
MrRAT preview

MrRAT

GitHubuser696/mrrat

:mouse: This is a cross-platform Python 2.x Remote Access Trojan (RAT)

command-and-controlencryption-decryption-toolspayload-development+3
149 years ago
cve-2017-12945 preview

cve-2017-12945

GitHubaress31/cve-2017-12945

Exploit for CVE-2017-12945.

command-and-controlexploitationpenetration-testing+3
46 years ago
StrutsShell preview

StrutsShell

GitHubfalcon-lnhg/strutsshell

Interactive command-line shell for exploiting Apache Struts CVE-2017-5638. Automates HTTP/HTTPS exploitation with real-time shell interaction on…

command-and-controlexploitationpenetration-testing+3
39 years ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubdynamo2k1/cve-2026-33017

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

command-and-controlexploitationpayload-generation+4
1 month ago
Ashwesker-CVE-2025-64155 preview

Ashwesker-CVE-2025-64155

GitHubmefhika120/ashwesker-cve-2025-64155

CVE-2025-64155

command-and-controlexploitationpenetration-testing+3
7 months ago
pupy preview
Archived

pupy

GitHubn1nj4sec/pupy

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

android-securitycommand-and-controllateral-movement+5
9.0k2 years ago
Previous1…131415Next