Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
135 results
DCVC2 preview

DCVC2

GitHub3nailsinfosec/dcvc2

Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

command-and-controldata-exfiltrationpayload-development+2
131
1 year ago
dns-black-cat preview

dns-black-cat

GitHubzux0x3a/dns-black-cat

Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

command-and-controldata-exfiltrationdns-analysis+3
1123 years ago
BounceBack preview

BounceBack

GitHubd00movenok/bounceback

↕️🤫 Stealth redirector for your red team operation security

command-and-controlids-ips-evasionpenetration-testing+3
1.1k1 month ago
Antecursor preview

Antecursor

GitLabantecursor/antecursor

Autonomous, modular open-hardware system for network reconnaissance, man-in-the-middle data collection, and automated exploitation with remote C2…

command-and-controlexploitationhardware-iot-security+5
57 years ago
webhandler preview

webhandler

GitHublnxg33k/webhandler

Bash simulator to control a server using PHP system functions.

command-and-controlids-ips-evasionpayload-generation+3
1005 years ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
38.9k17h 29m ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.7k4 days ago
BlackLotus preview

BlackLotus

GitHubldpreload/blacklotus

UEFI bootkit for Windows with Secure Boot bypass, kernel-level persistence, and encrypted HTTPS C2. Features HVCI/UAC bypass, API hooking, and…

command-and-controldefensive-toolsexploitation+8
2.2k2 years ago
b374k preview

b374k

GitHubb374k/b374k

Single-file PHP webshell providing remote file management, command execution, bind/reverse shell, database connectivity, and process control for…

command-and-controldatabase-securitypenetration-testing+2
2.7k3 years ago
odat preview

odat

GitHubquentinhardy/odat

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

command-and-controldatabase-securityexploitation+4
1.8k4 months ago
Remote-Access-Trojan preview

Remote-Access-Trojan

GitHubmalwares/remote-access-trojan

Windows-based remote access trojan (RAT) for covert system control, payload delivery, and data exfiltration. Intended for authorized security…

command-and-controldata-exfiltrationpayload-development+3
7509 years ago
WMImplant preview

WMImplant

GitHubredsiege/wmimplant

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

command-and-controlinformation-gatheringlateral-movement+3
8652 years ago
SharpWMI preview

SharpWMI

GitHubghostpack/sharpwmi

C# implementation of WMI for remote process creation, VBS execution, file upload, and system enumeration with alternate credential support and AMSI…

command-and-controlinformation-gatheringlateral-movement+5
7675 years ago
PCShare preview

PCShare

GitHubxdnice/pcshare

HTTP-based remote access tool with DLL injection, process hollowing, and system hooking for persistent control, screen monitoring, file exfiltration,…

command-and-controldata-exfiltrationlateral-movement+9
5699 years ago
paradoxiaRAT preview

paradoxiaRAT

GitHubquantumcore/paradoxiarat

Native Windows remote access tool with stealth client, reflective DLL injection, keylogger, Chrome password recovery, reverse shell, file system…

command-and-controlpassword-crackingpenetration-testing+4
8263 years ago
RSPET preview

RSPET

GitHubpanagiks/rspet

Python-based reverse shell with TLS encryption, file transfer, UDP flooding/spoofing, plugin system, and RESTful API for post-exploitation and red…

command-and-controlexploitationpayload-generation+4
2638 years ago
grc2 preview

grc2

GitHubandreiverse/grc2

Lightweight C2 framework written in Nim for generating implants, managing listeners, and executing tasks via TCP/HTTP with a loot system for…

command-and-controlpayload-generationred-teaming+1
3453 years ago
SirepRAT preview

SirepRAT

GitHubsafebreach-labs/sireprat

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

command-and-controlexploitationiot-security+4
3895 years ago
Previous12…8Next