Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
152 results
vger preview

vger

GitHubjosephtlucas/vger

An interactive CLI application for interacting with authenticated Jupyter instances.

ai-securitycommand-and-controlexploitation+8
571 year ago
PAKURI-THON preview

PAKURI-THON

GitHub01rabbit/pakuri-thon

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

command-and-controlexploit-frameworksinformation-gathering+7
284 years ago
cua-kit preview

cua-kit

GitHubpreludeorg/cua-kit

Tools for attacking Computer Use Agents

ai-securitycommand-and-controlexploitation+7
338 months ago
dicerosbicornis preview

dicerosbicornis

GitHubmaldevel/dicerosbicornis

A fully featured Windows backdoor that uses email as a C&C server

command-and-controldata-exfiltrationencryption-decryption-tools+5
169 years ago
APT-GUID preview

APT-GUID

GitHubal1ex/apt-guid

APT-GUID

command-and-controlcurated-resourceseducation+8
235 years ago
fronthunter preview

fronthunter

GitHubst3rven/fronthunter

FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.

command-and-controlinformation-gatheringreconnaissance+2
221 year ago
Social-media-c2 preview

Social-media-c2

GitHubwoj-ciech/social-media-c2

Script is a proof of concept how to control your machine by using social media sites.

command-and-controlinformation-gatheringosint-social-engineering+3
238 years ago
LSTAR-EN preview

LSTAR-EN

GitHubmoscowchill/lstar-en

LSTAR - CobaltStrike Translated to EN

command-and-controlexploitationids-ips-evasion+9
233 years ago
UltraRealy_with_CVE-2019-1040 preview

UltraRealy_with_CVE-2019-1040

GitHublazaars/ultrarealy_with_cve-2019-1040

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

authenticationcommand-and-controlexploitation+7
197 years ago
R2C-CVE-2025-55182-66478 preview

R2C-CVE-2025-55182-66478

GitHubcybertechajju/r2c-cve-2025-55182-66478

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+8
2410 months ago
CVE-2024-29973 preview

CVE-2024-29973

GitHubbigb0x/cve-2024-29973

POC for CVE-2024-29973

command-and-controlexploitationinformation-gathering+3
102 years ago
PhaseHack preview

PhaseHack

GitHubmalwaretech/phasehack

Phase C&C Blind SQL Injection

command-and-controlinformation-gatheringvulnerability-analysis+1
1011 years ago
XeytanWxCpp-RAT preview

XeytanWxCpp-RAT

GitHubmelardev/xeytanwxcpp-rat

Work in Progress. RAT written in C++ using wxWidgets

command-and-controlinformation-gatheringpayload-development+3
117 years ago
strutsy preview

strutsy

GitHubtahmed11/strutsy

Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability

command-and-controlexploitationinformation-gathering+3
108 years ago
waybend preview

waybend

GitHubprinciplebreach/waybend

Self-hosted SSRF redirect, payload, callback, and DNS workbench

command-and-controldns-analysisinformation-gathering+9
526 days ago
nimrm preview

nimrm

GitHubblue0x1/nimrm

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

authenticationcommand-and-controlinformation-gathering+6
627 days ago
Apache_Penetration_Tool preview

Apache_Penetration_Tool

GitHubwangfly-me/apache_penetration_tool

CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具

command-and-controlexploitationinformation-gathering+3
143 years ago
nimux preview

nimux

GitHubblue0x1/nimux

Pure-Nim network enumeration and remote execution toolkit for authorized security assessments. Supports SMB, LDAP, Kerberos, WinRM, database clients,…

authenticationcommand-and-controlexploitation+6
94 days ago
Previous1…567…9Next