Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
715 results
CVE-2024-41570 preview

CVE-2024-41570

GitHubdiemoeve/cve-2024-41570

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

command-and-controlexploitationpayload-generation+5
111 year ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubeynaexp/cve-2025-55182-poc

Poc for CVE-2025-55182 (remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including…

command-and-controleducationexploitation+3
69 months ago
C2 preview

C2

GitHubet0x/c2

Methods of C2

command-and-controlpayload-developmentpayload-generation+3
2111 years ago
PolyDrop preview

PolyDrop

GitHubmalwaresupportgroup/polydrop

A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit

command-and-controldefensive-toolseducation+5
1252 years ago
zoneminder-snapshots-rce-poc preview

zoneminder-snapshots-rce-poc

GitHubm3m0o/zoneminder-snapshots-rce-poc

This is a script written in Python that allows the exploitation of the Zoneminder's security flaw described in CVE-2023-26035.

command-and-controlexploitationpenetration-testing+3
2 years ago
bt2 preview

bt2

GitHubblazeinfosec/bt2

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

command-and-controlpayload-developmentpenetration-testing+3
20610 years ago
pybeacon preview

pybeacon

GitHubnccgroup/pybeacon

A collection of scripts for dealing with Cobalt Strike beacons in Python

command-and-controlencryption-decryption-toolsexploitation+3
1685 years ago
sleep_python_bridge preview

sleep_python_bridge

GitHubcobalt-strike/sleep_python_bridge

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

command-and-controlioc-managementlog-analysis+3
1881 year ago
AutoFunkt preview

AutoFunkt

GitHubredsiege/autofunkt

Python script for automating the creation of serverless cloud redirectors from Cobalt Strike malleable C2 profiles

cloud-securitycommand-and-controlred-teaming
2042 years ago
CVE-2026-69212 preview

CVE-2026-69212

GitHubc0gnit00/cve-2026-69212

Python poc, exploit for CVE-2025-69212

command-and-controlexploitationpayload-development+3
22 months ago
CVE-2018-1049-POC preview

CVE-2018-1049-POC

GitHublukehebe/cve-2018-1049-poc

Remote privilege escalation exploit for CVE-2018-1049 targeting VyOS via SSH-based command injection in a sudo-permitted Perl script, granting root…

command-and-controlexploitationpenetration-testing+3
7 months ago
CVE-2020-15778-Exploit preview

CVE-2020-15778-Exploit

GitHubneko-chanqwq/cve-2020-15778-exploit

Exploit for CVE-2020-15778(OpenSSH vul)

command-and-controlexploitationpayload-generation+3
384 years ago
cve-2025-8110-GOGS-RCE preview

cve-2025-8110-GOGS-RCE

GitHubkayl22/cve-2025-8110-gogs-rce

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

command-and-controlexploitationpayload-development+4
44 months ago
msf-remote-console preview
Archived

msf-remote-console

GitHubqubasa/msf-remote-console

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

command-and-controlexploit-frameworkspayload-development+3
577 years ago
Apache-Struts-2-CVE-2017-5638-Exploit- preview

Apache-Struts-2-CVE-2017-5638-Exploit-

GitHubr4v3nbl4ck/apache-struts-2-cve-2017-5638-exploit-

Exploit created by: R4v3nBl4ck end Pacman

command-and-controlexploitationpenetration-testing+3
39 years ago
hfs-cve-2014-6287-exploit preview

hfs-cve-2014-6287-exploit

GitHubfrancescobrina/hfs-cve-2014-6287-exploit

Python-based exploit for CVE-2014-6287 in HTTP File Server 2.3.x, delivering a reverse shell via Base64-encoded PowerShell payload for authorized…

command-and-controleducationexploitation+5
1 year ago
Octopus preview

Octopus

GitHubmhaskar/octopus

Open source pre-operation C2 server based on python and powershell

command-and-controlencryption-decryption-toolsinformation-gathering+3
7635 years ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1176 years ago
Previous123…40Next