Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
Empire preview
Archived

Empire

GitHubempireproject/empire

Empire is a PowerShell and Python post-exploitation agent.

command-and-controlexploitationlateral-movement+6
7.9k
6 years ago
Empire preview

Empire

GitHubbc-security/empire

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

adversarial-attackcommand-and-controlids-ips-evasion+5
5.3k19 days ago
Octopus preview

Octopus

GitHubmhaskar/octopus

Open source pre-operation C2 server based on python and powershell

command-and-controlencryption-decryption-toolsinformation-gathering+3
7635 years ago
Kraken preview

Kraken

GitHubkraken-ng/kraken

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

command-and-controlpayload-generationred-teaming+1
5552 years ago
AlanFramework preview

AlanFramework

GitHubenkomio/alanframework

A C2 post-exploitation framework

command-and-controlencryption-decryption-toolslateral-movement+7
4862 years ago
WSC2 preview

WSC2

GitHubarno0x/wsc2

A WebSocket C2 Tool

command-and-controlexploitationpayload-generation+2
4328 years ago
RedPeanut preview

RedPeanut

GitHubb4rtik/redpeanut

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

command-and-controlexploit-frameworkspayload-generation+7
3306 years ago
DBC2 preview

DBC2

GitHubarno0x/dbc2

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

command-and-controlpayload-generationpenetration-testing-frameworks+2
3268 years ago
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
3003 years ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2344 months ago
DNS-Persist preview

DNS-Persist

GitHub0x09al/dns-persist

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

command-and-controldns-analysispayload-generation+5
2078 years ago
FruityC2 preview

FruityC2

GitHubxtr4nge/fruityc2

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

command-and-controlexploit-frameworkspayload-development+4
2068 years ago
DropboxC2C preview

DropboxC2C

GitHub0x09al/dropboxc2c

DropboxC2C is a post-exploitation agent which uses Dropbox Infrastructure for command and control operations.

command-and-controlpayload-generationpost-exploitation+1
1537 years ago
outis preview

outis

GitHubsyss-research/outis

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

command-and-controldns-analysispayload-generation+3
1268 years ago
WebDavC2 preview

WebDavC2

GitHubarno0x/webdavc2

A WebDAV PROPFIND C2 tool

command-and-controlpayload-generationpenetration-testing+1
1208 years ago
Loki.Rat preview

Loki.Rat

GitHubthegeekht/loki.rat

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

command-and-controldata-exfiltrationlateral-movement+6
763 years ago
log4j-poc preview

log4j-poc

GitHubcyberxml/log4j-poc

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

educationexploitationlabs-practice+4
723 years ago
CVE-2019-2618 preview

CVE-2019-2618

GitHubpyn3rd/cve-2019-2618

Weblogic Unrestricted File Upload

exploitationpayload-generationpenetration-testing+2
547 years ago
Previous12Next