Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
CVE-2023-24489-ShareFile preview

CVE-2023-24489-ShareFile

GitHubadhikara13/cve-2023-24489-sharefile

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

command-and-controlexploitationpenetration-testing+3
13
3 years ago
CVE-2024-39943-Poc preview

CVE-2024-39943-Poc

GitHubheyholiday067/cve-2024-39943-poc

CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated…

command-and-controlexploitationpenetration-testing+2
2 years ago
PoshC2 preview

PoshC2

GitHubnettitude/poshc2

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

command-and-controllateral-movementpayload-generation+3
2.1k9 months ago
Atomic-Red-Team-C2 preview

Atomic-Red-Team-C2

GitHubdarmado/atomic-red-team-c2

ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via…

command-and-controlexploit-frameworkspayload-generation+3
1781 year ago
flightsim preview

flightsim

GitHubalphasoc/flightsim

A utility to safely generate malicious network traffic patterns and evaluate controls.

command-and-controldefensive-toolsdns-analysis+4
1.4k2 years ago
CVE-2024-4358_Mass_Exploit preview

CVE-2024-4358_Mass_Exploit

GitHubsk1dr0wz/cve-2024-4358_mass_exploit
command-and-controlexploitationpenetration-testing+3
242 years ago
CVE-2020-8165 preview

CVE-2020-8165

GitHubhybryx/cve-2020-8165
command-and-controlexploitationpayload-generation+3
45 years ago
CVE-2022-46169_poc preview

CVE-2022-46169_poc

GitHubdeval3x/cve-2022-46169_poc
command-and-controlexploitationpenetration-testing+2
3 years ago
Empire preview

Empire

GitHubbc-security/empire

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

adversarial-attackcommand-and-controlids-ips-evasion+5
5.3k19 days ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6374 years ago
Beaconator preview

Beaconator

GitHubcapt-meelo/beaconator

A beacon generator using Cobalt Strike and a variety of tools.

command-and-controlexploit-frameworkspayload-generation+2
4465 years ago
BetterBackdoor preview

BetterBackdoor

GitHubthatcherclough/betterbackdoor

A backdoor with a multitude of features.

command-and-controldata-exfiltrationpassword-cracking+4
2931 year ago
Elevate-System-Trusted-BOF preview

Elevate-System-Trusted-BOF

GitHubmr-un1k0d3r/elevate-system-trusted-bof
command-and-controlpayload-developmentpost-exploitation+2
1813 years ago
PayloadAutomation preview

PayloadAutomation

GitHubemcghee/payloadautomation
command-and-controlioc-managementpayload-development+3
1204 years ago
carina preview

carina

GitHubcodelatteid/carina

Webshell, Virtual Private Server (VPS) and cPanel Database

command-and-controldatabase-securitypenetration-testing+1
383 years ago
CVE-2020-17530 preview

CVE-2020-17530

GitHubal1ex/cve-2020-17530

S2-061 CVE-2020-17530

command-and-controleducationexploitation+3
295 years ago
mcp-pwn preview

mcp-pwn

GitHubjf-gondim/mcp-pwn

PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling…

command-and-controleducationexploitation+4
2 months ago
CVE-2022-46169 preview

CVE-2022-46169

GitHub0xn7y/cve-2022-46169

Exploit for CVE-2022-46169

authentication-authorizationcommand-and-controlexploitation+3
12 years ago
Previous1234Next