Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
Empire preview

Empire

GitHubbc-security/empire

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

adversarial-attackcommand-and-controlids-ips-evasion+5
5.3k
19 days ago
CVE-2026-63077 preview

CVE-2026-63077

GitHubanggatechi/cve-2026-63077

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…

exploitationpayload-developmentpenetration-testing+2
12 days ago
PyHmmm preview

PyHmmm

GitHubcodextf2/pyhmmm

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

command-and-controleducationpayload-development+2
862 years ago
defcon33_silence_kill_edr preview

defcon33_silence_kill_edr

GitHubarosenmund/defcon33_silence_kill_edr
adversarial-attackeducationlabs-practice+6
3461 year ago
PHP-8.1.0-dev-Backdoor preview

PHP-8.1.0-dev-Backdoor

GitHubk3ystr0k3r/php-8.1.0-dev-backdoor

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

exploitationpayload-developmentsupply-chain-security+3
11 month ago
CVE-2025-59712_CVE-2025-59713 preview

CVE-2025-59712_CVE-2025-59713

GitHubsynacktiv/cve-2025-59712_cve-2025-59713

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

exploitationpayload-developmentpenetration-testing+3
210 months ago
exploitgym preview

exploitgym

GitHubsunblaze-ucb/exploitgym

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

ai-securitybinary-exploitationctf+9
80115 days ago
DeepTrap preview

DeepTrap

GitHubzjuicsr/deeptrap

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

adversarial-attackai-securitycommand-and-control+8
103 months ago
apfell preview

apfell

GitHubmythicagents/apfell

JavaScript for Automation (JXA) macOS agent

command-and-controlexploit-frameworkspayload-development+3
10522 days ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
20821 days ago
octohook preview

octohook

GitHubdsnezhkov/octohook

Git Web Hook Tunnel for C2

command-and-controlpayload-developmentpenetration-testing+2
282 years ago
LitterBox preview

LitterBox

GitHubblacksnufkin/litterbox

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end…

ai-securitydynamic-analysis-sandboxingmalware-analysis+4
1.5k3 months ago
Maverick preview

Maverick

GitHubblacksnufkin/maverick

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

binary-analysiscommand-and-controlencryption-decryption-tools+5
1142 months ago
BlockchainC2 preview

BlockchainC2

GitHubxpn/blockchainc2

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

command-and-controlexploitationpayload-development+2
797 years ago
CVE-2022-26503 preview

CVE-2022-26503

GitHubsinsinology/cve-2022-26503
binary-exploitationexploitationpayload-development+2
104 years ago
CVE-2025-27480 preview

CVE-2025-27480

GitHubmrk336/cve-2025-27480

CVE-2025-27480 exposes a buffer overflow in OpenSSH 8.9p1 via a malformed SSH_USERAUTH packet. Attackers can inject shellcode and gain SYSTEM-level…

binary-exploitationeducationexploitation+5
11 months ago
CVE-2025-27237 preview

CVE-2025-27237

GitHubhackinglz/cve-2025-27237

CVE 2025 27237 Zabbix LPE proof of concept.

binary-analysiscode-analysisexploitation+3
206 months ago
CVE-2024-22515-File-Upload-Vulnerability preview

CVE-2024-22515-File-Upload-Vulnerability

GitHuborange-418/cve-2024-22515-file-upload-vulnerability
exploitationpayload-developmentpenetration-testing+2
2 years ago
Previous123Next