Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
200 results
CobaltBus preview

CobaltBus

GitHubflangvik/cobaltbus

Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus

cloud-securitycommand-and-controlexploit-frameworks+1
249
4 years ago
mythic_telegram_profile preview

mythic_telegram_profile

GitHubdavidcarliez/mythic_telegram_profile

Mythic C2 profile that tunnels Athena and Apollo agent traffic through Telegram bot-to-bot messages, bridging encrypted payloads to Mythic via its…

command-and-controlencryption-decryption-toolsexploit-frameworks+5
414 days ago
pystinger preview

pystinger

GitHubfunnywolf/pystinger

Bypass firewall for traffic forwarding using webshell

command-and-controlexploit-frameworksids-ips-evasion+5
1.4k5 years ago
GraphStrike preview

GraphStrike

GitHubredsiege/graphstrike

Cobalt Strike HTTPS beaconing over Microsoft Graph API

api-securitycloud-securitycommand-and-control+3
6382 years ago
c2 preview

c2

GitHubaveragesecurityguy/c2

A simple, extensible C&C beaconing system.

command-and-controlexploit-frameworksnetwork-security+3
1048 years ago
Covenant preview

Covenant

GitHubcobbr/covenant

Covenant is a collaborative .NET C2 framework for red teamers.

command-and-controlexploit-frameworkspayload-generation+2
4.7k5 years ago
Villain preview

Villain

GitHubt3l3machus/villain

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

command-and-controlexploit-frameworkspayload-generation+4
4.5k1 year ago
phpsploit preview

phpsploit

GitHubnil0x42/phpsploit

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

command-and-controlexploit-frameworkspayload-development+6
2.5k2 years ago
Nebula preview

Nebula

GitHubgl4ssesbo1/nebula

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

cloud-securitycommand-and-controlexploit-frameworks+3
6341 year ago
Nimbo-C2 preview

Nimbo-C2

GitHubitaymigdal/nimbo-c2

Nimbo-C2 is yet another (simple and lightweight) C2 framework

command-and-controlexploit-frameworkspayload-generation+5
4478 months ago
Maverick preview

Maverick

GitHubblacksnufkin/maverick

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

binary-analysiscommand-and-controlencryption-decryption-tools+5
1204 months ago
c2-cloud preview

c2-cloud

GitHubgovindasamyarun/c2-cloud

The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised…

command-and-controlexploit-frameworkspayload-generation+4
1282 years ago
Kitsune preview

Kitsune

GitHubjoelgmsec/kitsune

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

command-and-controlexploit-frameworkspayload-generation+2
1051 year ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

cloud-securitycommand-and-controlencryption-decryption-tools+6
4329 days ago
endgame preview

endgame

GitHubendgamec2framework/endgame

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

ai-securitycommand-and-controleducation+8
352 days ago
Cheshire preview

Cheshire

GitHubblacksnufkin/cheshire

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

command-and-controldynamic-analysis-sandboxingexploit-frameworks+4
665 months ago
lockjaw preview

lockjaw

GitHubg13net/lockjaw

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

command-and-controldns-analysisexploit-frameworks+9
269 days ago
adaptix-serverless-c2 preview

adaptix-serverless-c2

GitHubstillbigjosh/adaptix-serverless-c2

Serverless C2 transport plugin for AdaptixC2 v1.2 using AWS Lambda + DynamoDB as the relay infrastructure.

cloud-infrastructure-securitycloud-securitycommand-and-control+8
198 days ago
Previous12…12Next