Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
pyMalleableC2 preview

pyMalleableC2

GitHubbyt3bl33d3r/pymalleablec2

Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.

command-and-controlpayload-developmentred-teaming+1
290
2 months ago
Nebula preview

Nebula

GitHubgl4ssesbo1/nebula

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

cloud-securitycommand-and-controlexploit-frameworks+3
6371 year ago
CcmMessagingBackdoor preview

CcmMessagingBackdoor

GitHubsynacktiv/ccmmessagingbackdoor

Proof-of-concept backdoor for SCCM Management Point using rogue COM service for persistent remote command execution as SYSTEM.

command-and-controlpayload-developmentpersistence-mechanisms+3
191 year ago
Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis preview

Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis

GitHubkaandemir993/salat-stealer-telegram-proxy-decoy-c2-analysis

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

binary-analysiscommand-and-controleducation+6
51 month ago
c2s preview

c2s

GitHubj3ssie/c2s

Command and Control server on Slack

command-and-controlpenetration-testingpost-exploitation+2
307 years ago
CVE-2020-15778 preview

CVE-2020-15778

GitHubyifanzhg/cve-2020-15778

Reproduces CVE-2020-15778 SCP command injection exploit with Docker-based client-server setup for testing remote code execution and reverse shell…

command-and-controlcontainer-securityexploitation+3
32 years ago
Noregressh preview

Noregressh

GitHubohhdamnbro/noregressh

CVE-2024-6387 and more Checker and Exploiter - Reverse/Bind-Shell Support. education only

command-and-controlexploitationinformation-gathering+6
211 months ago
outis preview

outis

GitHubsyss-research/outis

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

command-and-controldns-analysispayload-generation+3
1268 years ago
DaaC2 preview

DaaC2

GitHubcrawl3r/daac2

Discord as a C2

command-and-controlpayload-generationred-teaming+1
515 years ago
SourcePoint preview

SourcePoint

GitHubtylous/sourcepoint

Polymorphic C2 profile generator for Cobalt Strike that automates creation of evasive beacon configurations with randomized options for HTTP, DNS,…

command-and-controlexploit-frameworkspayload-generation+1
1.2k1 year ago
Evilginx-Phishing-Infra-Setup preview

Evilginx-Phishing-Infra-Setup

GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

command-and-controlcurated-resourceseducation+6
6041 year ago
DCOMIllusionist preview

DCOMIllusionist

GitHubsynacktiv/dcomillusionist

DCOM in memory and fileless lateral movement techniques through .Net deserilization

authenticationcommand-and-controlexploitation+7
2902 months ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6374 years ago
CVE-2025-15545 preview

CVE-2025-15545

GitHubxernary/cve-2025-15545

Proof of Concept for CVE-2025-15545

command-and-controlembedded-systems-securityexploitation+3
17 months ago
botnet-hackpack preview

botnet-hackpack

GitHubtreehacks/botnet-hackpack

Build a basic Command & Control botnet in C

command-and-controleducationmalware-analysis+3
4057 years ago
smokedmeat preview

smokedmeat

GitHubboostsecurityio/smokedmeat

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

cloud-securitycommand-and-controleducation+9
3751 month ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub0xbinder/cve-2021-4045

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

command-and-controlexploitationhardware-iot-security+3
92 years ago
pentestproxy preview
Archived

pentestproxy

GitHubshiva108/pentestproxy

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

command-and-controldns-analysisids-ips-evasion+4
227 months ago
Previous12Next