Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
pwncat preview

pwncat

GitHubcalebstewart/pwncat

Post-exploitation platform automating enumeration, privilege escalation, persistence, and C2 operations via reverse/bind shells with cross-platform…

command-and-controlpenetration-testingpersistence-mechanisms+3
2.9k
4 years ago
Nebula preview

Nebula

GitHubgl4ssesbo1/nebula

Modular cloud penetration testing framework with teamserver-client architecture for reconnaissance, enumeration, exploitation, and post-exploitation…

cloud-securitycommand-and-controlexploit-frameworks+3
6361 year ago
ActiveReign preview

ActiveReign

GitHubm8sec/activereign

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

command-and-controlexploitationinformation-gathering+2
2462 years ago
WMImplant preview

WMImplant

GitHubredsiege/wmimplant

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

command-and-controlinformation-gatheringlateral-movement+3
8652 years ago
SharpWMI preview

SharpWMI

GitHubghostpack/sharpwmi

C# implementation of WMI for remote process creation, VBS execution, file upload, and system enumeration with alternate credential support and AMSI…

command-and-controlinformation-gatheringlateral-movement+5
7675 years ago
BOF_Collection preview

BOF_Collection

GitHubrvrsh3ll/bof_collection

Cobalt Strike BOFs for in-memory post-exploitation: Active Directory enumeration, clipboard capture, WiFi credential dump, port scan, and registry…

command-and-controlinformation-gatheringpersistence-mechanisms+4
7853 years ago
telegram-c2 preview

telegram-c2

GitHubtomiwa-ot/telegram-c2

Telegram bot-based C2 framework for remote system control, file exfiltration, screen/webcam capture, and service enumeration with stealthy deployment.

command-and-controlinformation-gatheringpersistence-mechanisms+4
491 year ago
ntlm_relay_gat preview

ntlm_relay_gat

GitHubad0nis/ntlm_relay_gat

Automates NTLM relay exploitation using ntlmrelayx.py for SMB share enumeration, shell execution, secrets dumping, and MSSQL command execution via…

command-and-controlexploitationinformation-gathering+5
1712 years ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1287 years ago
OneLogicalMyth_Shell preview

OneLogicalMyth_Shell

GitHubnccgroup/onelogicalmyth_shell

HTA-based post-exploitation shell for breakout assessments. Provides file explorer, system reconnaissance, AD enumeration, and file transfer…

command-and-controldata-exfiltrationpenetration-testing+3
1114 years ago
f5-bigip-rce-cve-2020-5902 preview

f5-bigip-rce-cve-2020-5902

GitHubthelsa/f5-bigip-rce-cve-2020-5902

Automated CVE-2020-5902 detection and exploitation tool for F5 BIG-IP TMUI, supporting single/batch vulnerability checks, file read/write, user…

command-and-controlexploitationinformation-gathering+3
626 years ago
bmc_bladelogic preview

bmc_bladelogic

GitHubbao7uo/bmc_bladelogic

Exploit scripts for BMC BladeLogic RSCD agent vulnerabilities, enabling remote code execution, password changes, and user enumeration on Linux and…

command-and-controlexploitationpenetration-testing+3
206 years ago
THM-MagnusBilling-CVE-2023-30258-Exploit preview

THM-MagnusBilling-CVE-2023-30258-Exploit

GitHubcyb3rk0ala/thm-magnusbilling-cve-2023-30258-exploit

Step-by-step walkthrough exploiting CVE-2023-30258 (MagnusBilling RCE) and escalating privileges via fail2ban misconfiguration on a TryHackMe lab.…

command-and-controlctfeducation+7
15 days ago
CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC preview

CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC

GitHubcerberusmrxi/cve-2026-57588-nessus-xml-import-sql-injection-poc

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

command-and-controldatabase-securitydata-exfiltration+7
11 month ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
4 months ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

Exploit and post-exploitation framework for Next.js RSC (CVE-2025-55182), with interactive RCE, file transfer, persistence, enumeration, and privesc.

command-and-controlcontainer-escapedata-exfiltration+7
8 months ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
3817 days ago
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
1 month ago
Previous123Next