Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
GDir-Thief preview

GDir-Thief

GitHubantman1p/gdir-thief

Red Team tool for exfiltrating the target organization's Google People Directory that you have access to, via Google's API.

data-exfiltrationinformation-gatheringosint+1
58
5 years ago
bat preview

bat

GitHubrhzv0/bat

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…

command-and-controldata-exfiltrationlateral-movement+5
374 months ago
gimmepatz preview

gimmepatz

GitHub6mile/gimmepatz

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

api-securityauthentication-authorizationcloud-security+7
441 year ago
DLPwn preview

DLPwn

GitHubgryfman/dlpwn

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

bluetooth-securitycommand-and-controldata-exfiltration+5
246 months ago
Pegasus-Gram preview

Pegasus-Gram

GitHubsobri3195/pegasus-gram

Python-based keylogger and surveillance tool with Telegram C2, capturing keystrokes, screenshots, webcam, audio, clipboard, and system activity for…

command-and-controldata-exfiltrationinformation-gathering+2
131 year ago
SharpDNSExfil preview

SharpDNSExfil

GitHubaniqfakhrul/sharpdnsexfil

C# tool for exfiltrating files over DNS using XOR and asymmetric encryption, designed for red team engagements with restricted outbound connections.

command-and-controldata-exfiltrationdns-analysis+2
135 years ago
SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2 preview

SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2

GitHubdevinliggins14/smb-pentest-exploiting-cve-2007-2447-on-metasploitable-2

Step-by-step penetration testing lab exploiting Samba CVE-2007-2447 on Metasploitable 2 using Metasploit, demonstrating root compromise, credential…

command-and-controldata-exfiltrationeducation+6
1 year ago
cve-2026-28576 preview

cve-2026-28576

GitHubaayushbankar/cve-2026-28576

PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…

android-securitydata-exfiltrationexploitation+6
5 days ago
firefox_tunnel preview
Archived

firefox_tunnel

GitHubconviso-archives/firefox_tunnel

Browser-based C2 tunnel that exfiltrates payloads through Firefox's cookie.sqlite and auto-submitting HTML/JS, enabling stealthy firewall bypass for…

command-and-controldata-exfiltrationids-ips-evasion+5
618 years ago
bettercap preview

bettercap

GitHubbettercap/bettercap

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

bluetooth-securitydata-exfiltrationfingerprint-spoofing+16
20.0k1 month ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.9k1 day ago
adversary_emulation_library preview

adversary_emulation_library

GitHubcenter-for-threat-informed-defense/adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

curated-resourcesdata-exfiltrationdefensive-tools+5
2.2k1 year ago
NorthStarC2 preview

NorthStarC2

GitHubeng1ndes/northstarc2

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

command-and-controldata-exfiltrationinformation-gathering+6
2682 years ago
FFM preview

FFM

GitHubjusticerage/ffm

Freedom Fighting Mode: open source hacking harness

command-and-controldata-exfiltrationinformation-gathering+6
3495 months ago
blue-pigeon preview

blue-pigeon

GitHubbluepigeonproject/blue-pigeon

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

android-securitybluetooth-securitycommand-and-control+4
565 years ago
CVE-2022-3656 preview

CVE-2022-3656

GitHubmomika233/cve-2022-3656

Proof-of-concept exploit for CVE-2022-3656, a Chrome/Chromium vulnerability enabling theft of sensitive files like encrypted wallets and cloud…

data-exfiltrationexploitationvulnerability-analysis+1
383 years ago
CVE-2026-39047 preview

CVE-2026-39047

GitHubazhariramadhan/cve-2026-39047

Printer exploitation framework for security testing via raw port 9100, featuring PCL payload delivery, DoS bombing, C2 QR codes, phishing QR codes,…

data-exfiltrationexploitationnetwork-security+4
5 months ago
privacy-filter preview

privacy-filter

GitHubopenai/privacy-filter

Bidirectional token-classification model for PII detection and masking in text, with CLI for redaction, evaluation, and finetuning on-premises.

ai-securitydata-exfiltrationdefensive-tools+4
2.7k5 months ago
Previous1234Next