Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
ZeroPulse preview

ZeroPulse

GitHubjxroot/zeropulse

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

command-and-controlexploitationlateral-movement+8
146
9 months ago
chisel preview

chisel

GitHubjpillora/chisel

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

command-and-controldata-exfiltrationgeneral-purpose-utilities+8
16.6k1 month ago
sshuttle preview

sshuttle

GitHubsshuttle/sshuttle

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

command-and-controldata-exfiltrationdns-analysis+6
13.6k2 days ago
C2concealer preview

C2concealer

GitHubredsiege/c2concealer

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

command-and-controlpayload-generationpenetration-testing-frameworks+1
1.1k5 months ago
meterssh preview

meterssh

GitHubtrustedsec/meterssh

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

command-and-controlexploitationpayload-development+4
5309 years ago
SSHPry2.0 preview

SSHPry2.0

GitHubnopernik/sshpry2.0

SSHPry v2 - Spy & Control os SSH Connected client's TTY

command-and-controlphishing-toolspost-exploitation+2
4019 years ago
AzureC2Relay preview

AzureC2Relay

GitHubflangvik/azurec2relay

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

cloud-securitycommand-and-controlids-ips-evasion+2
2335 years ago
chisel-ng preview

chisel-ng

GitHubnullsection/chisel-ng

Chisel new generation, written in rust. SSH under WSS with some customization.

command-and-controlids-ips-evasionlateral-movement+5
1358 months ago
poc-proxycommand-vulnerable preview

poc-proxycommand-vulnerable

GitHubvin01/poc-proxycommand-vulnerable

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

command-and-controlexploitationlateral-movement+3
502 years ago
CVE-2026-4631-cockpit-RCE preview

CVE-2026-4631-cockpit-RCE

GitHubcyberheartmi9/cve-2026-4631-cockpit-rce

Cockpit: Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection

command-and-controlexploitationpenetration-testing+3
145 months ago
CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC preview

CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

GitHubomer-efe-curkus/cve-2025-32433-erlang-otp-ssh-rce-poc

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

command-and-controlexploitationnetwork-security+3
161 year ago
CVE-2025-67511 preview

CVE-2025-67511

GitHubedoardottt/cve-2025-67511

Detailed disclosure of CVE-2025-67511, a command injection vulnerability in the CAI framework's SSH tool that allows AI agents to be tricked into…

ai-securitycommand-and-controleducation+5
63 months ago
cve-2025-32433 preview

cve-2025-32433

GitHub0xpthree/cve-2025-32433

Python exploit for CVE-2025-32433 targeting Erlang OTP SSH server. Sends crafted SSH packets to open a reverse shell and gain root access.

command-and-controlexploitationpayload-generation+3
61 year ago
CVE-2025-32433 preview

CVE-2025-32433

GitHub0x7556/cve-2025-32433

CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP

command-and-controlexploitationpenetration-testing+3
33 months ago
CVE-2026-4631-cockpit-RCE preview

CVE-2026-4631-cockpit-RCE

GitHubexdev994/cve-2026-4631-cockpit-rce

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

command-and-controlexploitationinformation-gathering+6
2 months ago
CVE-2025-32433_Erlang-OTP_PoC preview

CVE-2025-32433_Erlang-OTP_PoC

GitHubabrewer251/cve-2025-32433_erlang-otp_poc

This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers

command-and-controlexploitationnetwork-security+3
11 year ago
Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE preview

Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE

GitHublu3ky13/alternative-approach-reverse-shell-callback-test-invokeai-rce

This repository contains alternative payload approaches for the InvokeAI RCE vulnerability (CVE-2024-12029) when SSH key injection fails. The…

command-and-controleducationexploitation+5
5 months ago
CVE-2026-48732-poc preview

CVE-2026-48732-poc

GitHubsaku0512/cve-2026-48732-poc

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

command-and-controleducationexploitation+3
3 months ago
Previous123Next