Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1048 results
azureOutlookC2 preview

azureOutlookC2

GitHubboku7/azureoutlookc2

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

api-securitycloud-securitycommand-and-control+2
5033 years ago
AzureC2Relay preview

AzureC2Relay

GitHubflangvik/azurec2relay

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

cloud-securitycommand-and-controlids-ips-evasion+2
2335 years ago
DarkAgent preview

DarkAgent

GitHubilikenwf/darkagent

DarkAgent Remote Administration Tool RAT by DragonHunter

command-and-controlpenetration-testingpost-exploitation+3
14313 years ago
SharpFtpC2 preview

SharpFtpC2

GitHubdarkcodersc/sharpftpc2

A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.

adversarial-attackcommand-and-controleducation+3
912 years ago
dark-doh preview

dark-doh

GitHubdarksh3llru/dark-doh

Covert file-transfer tool using DNS-over-HTTPS: encodes payload chunks in TXT records, applies XOR obfuscation, and can execute shellcode for…

command-and-controldata-exfiltrationred-teaming
202 years ago
Pegasus-Gram preview

Pegasus-Gram

GitHubsobri3195/pegasus-gram

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

command-and-controldata-exfiltrationinformation-gathering+2
131 year ago
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
527 days ago
CVE-2024-38472 preview

CVE-2024-38472

GitHubabdurahmon3236/cve-2024-38472

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

command-and-controlexploit-frameworkslateral-movement+6
42 years ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubozcanpng/cve-2024-9264

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

command-and-controleducationexploitation+3
1 month ago
cve-2025-66398 preview

cve-2025-66398

GitHubjoshuavanderpoll/cve-2025-66398

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

command-and-controleducationexploitation+7
36 months ago
CVE-2023-46805 preview

CVE-2023-46805

GitHubw2xim3/cve-2023-46805

CVE-2023-46805 Ivanti POC RCE - Ultra fast scanner.

command-and-controleducationexploitation+3
22 years ago
CVE-2025-10230 preview

CVE-2025-10230

GitHubnehkark/cve-2025-10230

CVE-2025-10230 PoC - Samba WINS Hook Command Injection

command-and-controleducationexploitation+3
19 months ago
CVE-2021-44228-log4Shell preview

CVE-2021-44228-log4Shell

GitHubkali-dass/cve-2021-44228-log4shell

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

command-and-controlexploitationpayload-generation+3
14 years ago
CVE-2024-47875-PhpSpreadsheet-XSS-PoC preview

CVE-2024-47875-PhpSpreadsheet-XSS-PoC

GitHubroj1py/cve-2024-47875-phpspreadsheet-xss-poc

This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln

command-and-controldata-exfiltrationexploitation+3
11 year ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubscroollocker/cve-2025-49132

Python exploit for CVE-2025-49132, enabling unauthenticated remote code execution on Pterodactyl Panel via crafted locale and namespace parameters.

command-and-controlexploitationpayload-development+3
7 months ago
CVE-2026-0709 preview

CVE-2026-0709

GitHubsnipersmaster/cve-2026-0709

Python proof-of-concept for authenticated command injection in Hikvision wireless APs, enabling remote code execution testing with customizable…

command-and-controlexploitationpenetration-testing+3
6 months ago
CVE-2024-10914-Exploit preview

CVE-2024-10914-Exploit

GitHubjahithoque/cve-2024-10914-exploit

Shell script exploiting CVE-2024-10914 for remote OS command injection in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L devices via cgi_user_add.

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubdevengpk/cve-2022-36804

Proof-of-concept exploit for CVE-2022-36804, a command injection vulnerability in Bitbucket Server and Data Center, enabling arbitrary code execution…

command-and-controlexploitationpenetration-testing+2
3 years ago
Previous1…363738…59Next