Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
690 results
s2-062 preview

s2-062

GitHubpyroxenites/s2-062

远程代码执行S2-062 CVE-2021-31805验证POC

command-and-controlexploitationpayload-generation+3
13210 months ago
CVE-2019-3396 preview

CVE-2019-3396

GitHubjas502n/cve-2019-3396

Confluence 未授权 RCE (CVE-2019-3396) 漏洞

command-and-controlexploitationpayload-development+3
1456 years ago
Kraken preview

Kraken

GitHubkraken-ng/kraken

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

command-and-controlpayload-generationred-teaming+1
5542 years ago
RedditC2 preview

RedditC2

GitHubkleiton0x00/redditc2

Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

command-and-controlexploitationpayload-development+1
2773 years ago
Brute-Ratel-C4-Community-Kit preview

Brute-Ratel-C4-Community-Kit

GitHubparanoidninja/brute-ratel-c4-community-kit

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

command-and-controlexploitationpayload-development+3
3032 years ago
CVE-2017-10271 preview

CVE-2017-10271

GitHubc0mmand3ropsec/cve-2017-10271

Unauthenticated remote code execution exploit for Oracle WebLogic CVE-2017-10271. Provides XML payload and endpoint list for penetration testing of…

command-and-controlexploitationpayload-generation+3
1438 years ago
CVE-2020-17144 preview

CVE-2020-17144

GitHubzcgonvh/cve-2020-17144

weaponized tool for CVE-2020-17144

command-and-controlexploitationpayload-generation+2
1585 years ago
pyMalleableC2 preview

pyMalleableC2

GitHubbyt3bl33d3r/pymalleablec2

Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.

command-and-controlpayload-developmentred-teaming+1
2893 months ago
DNS-Persist preview

DNS-Persist

GitHub0x09al/dns-persist

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

command-and-controldns-analysispayload-generation+5
2078 years ago
PwnLnX preview

PwnLnX

GitHubthatstraw/pwnlnx

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

command-and-controlpayload-generationpenetration-testing+3
2264 years ago
Girsh preview

Girsh

GitHubnodauf/girsh

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

command-and-controlexploitationpayload-generation+5
3593 years ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2967 months ago
Livepyre preview

Livepyre

GitHubsynacktiv/livepyre

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.

command-and-controlexploitationpayload-generation+3
1502 months ago
WebDavC2 preview

WebDavC2

GitHubarno0x/webdavc2

A WebDAV PROPFIND C2 tool

command-and-controlpayload-generationpenetration-testing+1
1209 years ago
backdoors preview

backdoors

GitHubhackerhouse-opensource/backdoors

Tools for maintaining access to systems and proof-of-concept demonstrations.

command-and-controlpayload-developmentpersistence-mechanisms+3
1838 months ago
CVE-2022-26134-Godzilla-MEMSHELL preview

CVE-2022-26134-Godzilla-MEMSHELL

GitHubbeichendream/cve-2022-26134-godzilla-memshell

Java-based exploit for CVE-2022-26134 that injects a Godzilla webshell into Confluence servers, enabling remote code execution with password and key…

command-and-controlexploitationpayload-generation+3
3384 years ago
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
2993 years ago
tsh-sctp preview

tsh-sctp

GitHubinfodox/tsh-sctp

TinySHell port to SCTP

command-and-controlpayload-developmentpenetration-testing+3
12512 years ago
Previous1…678…39Next