Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
733 results
Ninja preview

Ninja

GitHubahmedkhlief/ninja

Open source C2 server created for stealth red team operations

command-and-controlexploitationinformation-gathering+6
8404 years ago
Adrenaline preview

Adrenaline

GitHubatomiczsec/adrenaline

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

command-and-controldefensive-toolsinformation-gathering+7
31927 days ago
ActiveReign preview

ActiveReign

GitHubm8sec/activereign

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

command-and-controlexploitationinformation-gathering+2
2462 years ago
ntlm_relay_gat preview

ntlm_relay_gat

GitHubad0nis/ntlm_relay_gat

Automates NTLM relay exploitation using ntlmrelayx.py for SMB share enumeration, shell execution, secrets dumping, and MSSQL command execution via…

command-and-controlexploitationinformation-gathering+5
1712 years ago
Daily-dose-of-malware preview

Daily-dose-of-malware

GitHubwoj-ciech/daily-dose-of-malware

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

command-and-controlinformation-gatheringmalware-analysis+2
408 years ago
Xenotix-xBOT preview

Xenotix-xBOT

GitHubajinabraham/xenotix-xbot

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

command-and-controlexploitationinformation-gathering+4
288 years ago
vger preview

vger

GitHubjosephtlucas/vger

An interactive CLI application for interacting with authenticated Jupyter instances.

ai-securitycommand-and-controlexploitation+8
571 year ago
CVE-2024-29973 preview

CVE-2024-29973

GitHubbigb0x/cve-2024-29973

POC for CVE-2024-29973

command-and-controlexploitationinformation-gathering+3
102 years ago
XeytanWxCpp-RAT preview

XeytanWxCpp-RAT

GitHubmelardev/xeytanwxcpp-rat

Work in Progress. RAT written in C++ using wxWidgets

command-and-controlinformation-gatheringpayload-development+3
117 years ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubcoldfusionx/cve-2022-36804

Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)

command-and-controlexploitationinformation-gathering+3
73 years ago
Antecursor preview

Antecursor

GitLabantecursor/antecursor

Autonomous and modular system for network based information gathering and exploitation. WEB interface here: https://antecursor.fr/ More info…

command-and-controlexploitationhardware-iot-security+5
57 years ago
CVE-2025-52688 preview

CVE-2025-52688

GitHubjoelczk/cve-2025-52688

Proof-of-concept exploits for CVE-2025-52688: unauthenticated command injection and arbitrary file read vulnerabilities in Alcatel AP13161 enterprise…

command-and-controlexploitationhardware-iot-security+3
21 year ago
CVE-2022-28906-POC preview

CVE-2022-28906-POC

GitHubfinnvle/cve-2022-28906-poc

Python proof-of-concept for unauthenticated OS command injection in TOTOLINK N600R, exploiting the langType parameter to execute arbitrary commands…

command-and-controlexploitationhardware-iot-security+3
11 month ago
Harmonic preview

Harmonic

GitLabrunik/harmonic

Suite for reverse shell handling geared toward working within the native shell

command-and-controlinformation-gatheringpayload-development+7
8 years ago
Pyrescom-Termod-PoC preview

Pyrescom-Termod-PoC

GitHuboutpost24/pyrescom-termod-poc

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

authenticationcommand-and-controlexploitation+5
5 years ago
CrackMapExec preview
Archived

CrackMapExec

GitHubbyt3bl33d3r/crackmapexec

A swiss army knife for pentesting networks

command-and-controlexploitationinformation-gathering+5
9.2k2 years ago
GitHub-gato preview

GitHub-gato

GitHubgmh5225/github-gato

GitHub Self-Hosted Runner Enumeration and Attack Tool

command-and-controldefensive-toolsexploitation+6
13 years ago
Shadowbroker preview

Shadowbroker

GitHubbigbodycobain/shadowbroker

Real-time geospatial OSINT platform aggregating 60+ public telemetry feeds (ADS-B, AIS, satellites, CCTV) into a unified map with server-side recon…

command-and-controlcrawlerdns-analysis+7
11.3k2 days ago
Previous1234…41Next