Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
JS-Tap preview

JS-Tap

GitHubhoodoer/js-tap

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

command-and-controldata-exfiltrationinformation-gathering+8
482
3 months ago
reave preview

reave

GitHubpsmths/reave

WIP Post-exploitation framework tailored for hypervisors.

command-and-controldata-exfiltrationexploit-frameworks+8
513 years ago
DNS-Persist preview

DNS-Persist

GitHub0x09al/dns-persist

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

command-and-controldns-analysispayload-generation+5
2078 years ago
EvilOSX preview

EvilOSX

GitHubcys3c/evilosx

A pure python, post-exploitation, remote administration tool (RAT) for macOS / OS X.

command-and-controlencryption-decryption-toolspersistence-mechanisms+2
519 years ago
CVE-2025-49113-PoC preview

CVE-2025-49113-PoC

GitHubevillm/cve-2025-49113-poc

Post-authentication remote code execution proof-of-concept for CVE-2025-49113 in Roundcube webmail. Includes a vulnerable Docker environment and…

command-and-controlexploitationpayload-generation+3
8 months ago
DropboxC2C preview

DropboxC2C

GitHub0x09al/dropboxc2c

DropboxC2C is a post-exploitation agent which uses Dropbox Infrastructure for command and control operations.

command-and-controlpayload-generationpost-exploitation+1
1527 years ago
wikipedia-c2 preview

wikipedia-c2

GitHubdaniel-infosec/wikipedia-c2

POC for utilizing wikipedia API for Command and Control

api-securitycommand-and-controlexploitation+3
297 years ago
CVE-2026-42271-PoC preview

CVE-2026-42271-PoC

GitHublearner202649/cve-2026-42271-poc

The code for personally reproducing the corresponding vulnerability

command-and-controleducationexploitation+5
14 months ago
CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2 preview

CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2

GitHubsrginebras/cve-2026-23744-rce-for-mcpjam-inspector-v1.4.2

Python exploit for CVE-2026-23744 achieving remote code execution via crafted POST requests to the /api/mcp/connect endpoint in MCPJam Inspector <=…

command-and-controlexploitationpenetration-testing+3
14 months ago
terminalphone preview

terminalphone

GitLabhere_forawhile/terminalphone

Encrypted push-to-talk voice and text communication over Tor hidden services with end-to-end encryption, configurable ciphers, relay mode for group…

command-and-controlencryption-decryption-toolsnetwork-security+3
27122 days ago
Bella preview

Bella

GitHub00xglitch/bella

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

command-and-controldata-exfiltrationids-ips-evasion+8
2063 years ago
CVE-2018-11235 preview

CVE-2018-11235

GitHubrogdham/cve-2018-11235

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

command-and-controlexploitationpayload-generation+2
485 years ago
kubesploit preview

kubesploit

GitHubcyberark/kubesploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

command-and-controlcontainer-escapecontainer-security+8
1.2k1 year ago
mythic_telegram_profile preview

mythic_telegram_profile

GitHubdavidcarliez/mythic_telegram_profile

Mythic C2 profile that tunnels Athena and Apollo agent traffic through Telegram bot-to-bot messages, bridging encrypted payloads to Mythic via its…

command-and-controlencryption-decryption-toolsexploit-frameworks+5
413 days ago
cve-2022-30525 preview

cve-2022-30525

GitHubiveresk/cve-2022-30525

Proof-of-concept exploit for CVE-2022-30525 enabling unauthenticated remote command injection on Zyxel firewalls via HTTP POST requests to the…

command-and-controlexploitationpenetration-testing+2
34 years ago
CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ preview

CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ

GitHubmbanyamer/cve-2026-22553-insat-masterscada-buk-ts-mmadmserv

Unauthenticated OS command injection exploit for InSAT MasterSCADA BUK-TS MMadmServ web interface. Delivers reverse shell with root privileges via…

command-and-controlexploitationpayload-generation+3
4 months ago
CVE-2024-25180 preview

CVE-2024-25180

GitHubdustblessnotdust/cve-2024-25180

Python exploit script for CVE-2024-25180, a remote code execution vulnerability in pdfmake, delivering a reverse shell via crafted POST requests.

command-and-controlexploitationpayload-generation+3
1 year ago
Amnesiac preview

Amnesiac

GitHubleo4j/amnesiac

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

command-and-controllateral-movementpenetration-testing+2
4521 year ago
Previous12345Next