Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
736 results
Zeek-Intelligence-Feeds preview

Zeek-Intelligence-Feeds

GitHubcriticalpathsecurity/zeek-intelligence-feeds

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

command-and-controlintrusion-detectionnetwork-security+3
399
1h 59m ago
egressbuster preview

egressbuster

GitHubtrustedsec/egressbuster

Egressbuster is a method to check egress filtering and identify if ports are allowed. If they are, you can automatically spawn a shell.

command-and-controlnetwork-securitypenetration-testing
3745 years ago
sliver-tor-bridge preview

sliver-tor-bridge

GitHubotsmane-ahmed/sliver-tor-bridge

Tor transport bridge for Sliver C2 - anonymous command and control

command-and-controlnetwork-securitypayload-generation+2
607 months ago
PiX-C2 preview

PiX-C2

GitHubrobertdavis1/pix-c2

Ping Exfiltration Command and Control (PiX-C2)

command-and-controlnetwork-securitypacket-sniffing-analysis+3
3111 years ago
CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC preview

CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

GitHubomer-efe-curkus/cve-2025-32433-erlang-otp-ssh-rce-poc

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

command-and-controlexploitationnetwork-security+3
161 year ago
pingback preview

pingback

GitHubcorelight/pingback

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

command-and-controlintrusion-detectionmalware-analysis+2
1110 months ago
powercat preview

powercat

GitHubbesimorhino/powercat

netshell features all in version 2 powershell

command-and-controldns-analysisnetwork-security+5
2.4k2 years ago
snmp-shell preview

snmp-shell

GitHubmxrch/snmp-shell

Shell Simulation over Net-SNMP with extend functionality

command-and-controlexploitationnetwork-security+3
995 years ago
PowerProxy preview

PowerProxy

GitHubget-get-get-get/powerproxy

PowerShell SOCKS proxy with reverse proxy capabilities

command-and-controlnetwork-securitypenetration-testing+1
846 years ago
zeek-caldera-detector preview

zeek-caldera-detector

GitHubcorelight/zeek-caldera-detector

A Zeek based Mitre Caldera detector.

anomaly-detectioncommand-and-controlintrusion-detection+2
210 months ago
cisco-cve-2023-20198-checker preview

cisco-cve-2023-20198-checker

GitHubgustavorobertux/cisco-cve-2023-20198-checker
command-and-controlexploitationnetwork-security+3
5 months ago
zeek-spicy-facefish preview

zeek-spicy-facefish

GitHubcorelight/zeek-spicy-facefish

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

command-and-controlintrusion-detectionmalware-analysis+1
14 years ago
LOG4J-CVE-2021-44228 preview
Archived

LOG4J-CVE-2021-44228

GitHubsumitpathania03/log4j-cve-2021-44228
command-and-controlexploitationpacket-sniffing-analysis+3
3 years ago
Platypus preview

Platypus

GitHubwangyihang/platypus

:hammer: A modern, cross-platform machine manager

command-and-controlnetwork-securitypenetration-testing+2
1.7k2 months ago
gtunnel preview

gtunnel

GitHubhotnops/gtunnel

A robust tunelling solution written in golang

command-and-controlnetwork-securityred-teaming
2733 years ago
sshimpanzee preview

sshimpanzee

GitHublexfo/sshimpanzee

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

command-and-controldns-analysisnetwork-security+4
2941 year ago
RedCaddy preview

RedCaddy

GitHubxiaolichan/redcaddy

C2 redirector base on caddy

adversarial-attackanti-botcommand-and-control+3
2112 years ago
SeeProxy preview

SeeProxy

GitHubnopbrick/seeproxy

Golang reverse proxy with CobaltStrike malleable profile validation.

command-and-controlnetwork-securitypenetration-testing+1
1093 years ago
Previous12…41Next