Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
162
2 years ago
Cooolis-ms preview

Cooolis-ms

GitHubrvn0xsy/cooolis-ms

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

command-and-controlexploit-frameworksids-ips-evasion+7
9287 months ago
CobaltStrike-Toolset preview

CobaltStrike-Toolset

GitHubqax-a-team/cobaltstrike-toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

command-and-controlexploit-frameworkslateral-movement+8
5923 years ago
external_c2_framework preview

external_c2_framework

GitHubund3rf10w/external_c2_framework

Python api for usage with cobalt strike's External C2 specification

command-and-controlexploit-frameworkspayload-development+3
2394 years ago
ExternalC2 preview

ExternalC2

GitHubryhanson/externalc2

A library for integrating communication channels with the Cobalt Strike External C2 server

command-and-controlexploit-frameworkspayload-development+3
2898 years ago
CobaltBus preview

CobaltBus

GitHubflangvik/cobaltbus

Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus

cloud-securitycommand-and-controlexploit-frameworks+1
2474 years ago
Jasmin-Ransomware preview

Jasmin-Ransomware

GitHubcodesiddhant/jasmin-ransomware

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

command-and-controlencryption-decryption-toolsexploitation+5
2865 years ago
raven preview

raven

GitHubxorrior/raven

CobaltStrike External C2 for Websockets

command-and-controlexploit-frameworkspayload-development+3
1957 years ago
external_c2 preview

external_c2

GitHuboutflanknl/external_c2

POC for Cobalt Strike external C2

command-and-controlexploit-frameworkspayload-development+3
1434 years ago
external_c2_framework preview

external_c2_framework

GitHubtruneski/external_c2_framework

Python api for usage with cobalt strike's External C2 specification

command-and-controlexploit-frameworkspayload-development+3
637 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsickwell/cve-2025-55182

CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface

code-analysisexploitationpayload-development+3
138 months ago
voron-crypto preview

voron-crypto

GitHubsoftdeadlock/voron-crypto

Voron messenger crypto/protocol library (X3DH-lite + Double Ratchet, group sender-keys, onion transport) — external review requested

command-and-controlcryptographyencryption-decryption-tools+3
11 month ago
CVE-2025-11953-PoC preview

CVE-2025-11953-PoC

GitHubboroeurnprach/cve-2025-11953-poc

CVE-2025-11953 - The React Native Metro server's default external binding exposes a vulnerable endpoint, allowing unauthenticated attackers to…

exploitationpayload-developmentpenetration-testing+2
7 months ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
fawkes preview

fawkes

GitHubgaloryber/fawkes

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

cloud-securitycommand-and-controlcontainer-escape+7
361 month ago
CVE-2015-5254 preview

CVE-2015-5254

GitHubjas502n/cve-2015-5254

ActiveMQ Deserialization RCE

exploitationinformation-gatheringpayload-development+3
156 years ago
CVE-2019-13272 preview

CVE-2019-13272

GitHubjosemlwdf/cve-2019-13272

This is a Python 3 version of this exploit. Hope it works!!!

binary-exploitationexploitationpayload-development+3
31 year ago
CVE-2025-7766 preview
Archived

CVE-2025-7766

GitHubbytereaper77/cve-2025-7766

PoC exploit for CVE-2025-7766 – XXE vulnerability leading to potential RCE.

exploitationpayload-developmentpenetration-testing+2
11 year ago