Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
Boomerang preview

Boomerang

GitHubparanoidninja/boomerang

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

command-and-controllateral-movementpenetration-testing+1
226
5 years ago
CVE-2024-4358_Mass_Exploit preview

CVE-2024-4358_Mass_Exploit

GitHubsk1dr0wz/cve-2024-4358_mass_exploit

Mass exploitation tool for CVE-2024-4358, executing commands on multiple web targets concurrently with threading support.

command-and-controlexploitationpenetration-testing+3
252 years ago
Stowaway preview

Stowaway

GitHubph4ntonn/stowaway

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

command-and-controlencryption-decryption-toolslateral-movement+3
3.4k6 months ago
CVE-2019-16920-MassPwn3r preview

CVE-2019-16920-MassPwn3r

GitHubeniac888/cve-2019-16920-masspwn3r

Automated mass exploitation tool for CVE-2019-16920 command injection vulnerability in multiple D-Link routers, enabling unauthenticated remote code…

command-and-controlexploitationpenetration-testing+3
16 years ago
CVE-2026-23744-MCPJam-Exploit preview

CVE-2026-23744-MCPJam-Exploit

GitHubcerberusmrxi/cve-2026-23744-mcpjam-exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

command-and-controleducationexploitation+4
81 month ago
SSHPry2.0 preview

SSHPry2.0

GitHubnopernik/sshpry2.0

SSHPry v2 - Spy & Control os SSH Connected client's TTY

command-and-controlphishing-toolspost-exploitation+2
4008 years ago
cve-2022-1388-iveresk-command-shell preview

cve-2022-1388-iveresk-command-shell

GitHubiveresk/cve-2022-1388-iveresk-command-shell

Improved POC for CVE-2022-1388 that affects multiple F5 products.

command-and-controlexploitationpenetration-testing+3
14 years ago
Commander preview

Commander

GitHubvoukatas/commander

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

command-and-controlencryption-decryption-toolspayload-development+3
632 years ago
CVE-2025-47812 preview

CVE-2025-47812

GitHub0xjuarez/cve-2025-47812

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…

command-and-controlexploitationpenetration-testing+3
16 months ago
cve-2022-28944 preview

cve-2022-28944

GitHubgar-re/cve-2022-28944

Proof-of-concept exploit for unauthenticated remote code execution in EMCO Software products via DNS spoofing and malicious update injection.

command-and-controlexploitationpayload-development+3
43 years ago
CVE-2022-21350 preview

CVE-2022-21350

GitHubhktalent/cve-2022-21350

Exploit toolkit for CVE-2022-21350 targeting Oracle WebLogic T3 protocol with payload generation, LDAP/HTTP servers, and support for multiple JDK…

command-and-controlexploitationpayload-development+3
32 years ago
zuthaka preview

zuthaka

GitHubpucarasec/zuthaka

Open-source C2 integration framework providing a unified web interface for managing multiple command-and-control instances, listeners, agents, and…

command-and-controlexploit-frameworkspenetration-testing-frameworks+2
1813 years ago
CVE-2024-3273 preview

CVE-2024-3273

GitHubadhikara13/cve-2024-3273

Exploit for CVE-2024-3273, supports single and multiple hosts

command-and-controlexploitationpenetration-testing+3
132 years ago
PoC-RCE-CVE-2025-55182 preview

PoC-RCE-CVE-2025-55182

GitHubilixm/poc-rce-cve-2025-55182

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

command-and-controlexploitationinformation-gathering+7
8 months ago
AggressorScripts preview

AggressorScripts

GitHubharleyqu1nn/aggressorscripts

Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

command-and-controlinformation-gatheringpayload-generation+5
1.5k3 years ago
Drupalgeddon2-CVE-2018-7600 preview

Drupalgeddon2-CVE-2018-7600

GitHubbixipro/drupalgeddon2-cve-2018-7600

Python exploit for CVE-2018-7600 (Drupalgeddon 2) enabling remote code execution on Drupal 7 with multiple injection methods and predefined commands…

command-and-controleducationexploitation+3
6 months ago
ezsploit preview

ezsploit

GitHubrand0m1ze/ezsploit

Linux bash script automation for metasploit

command-and-controlexploit-frameworkspayload-development+5
26910 years ago
langflow-rce-exploit preview

langflow-rce-exploit

GitHub0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

command-and-controlexploitationpayload-development+8
71 year ago
Previous123Next