Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
1
4 days ago
Empire preview

Empire

GitHubbc-security/empire

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

adversarial-attackcommand-and-controlids-ips-evasion+5
5.3k19 days ago
G0BurpSQLmaPI preview

G0BurpSQLmaPI

GitHubnu11secur1ty/g0burpsqlmapi
exploitationpayload-generationpenetration-testing+2
31 month ago
EvilAhenk preview

EvilAhenk

GitHubjackalkarlos/evilahenk

CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod…

command-and-controlexploitationlateral-movement+7
21 month ago
Gideon preview

Gideon

GitHubcogensec/gideon

Autonomous security operations agent for threat intelligence, vulnerability research, IOC analysis, and red teaming. Supports dual-mode operations…

ai-securitycommand-and-controleducation+9
341 month ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2344 months ago
GeckoDroid preview

GeckoDroid

GitHubblacksnufkin/geckodroid

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

android-securitycommand-and-controlmobile-security+4
385 months ago
CVE-2025-13374 preview

CVE-2025-13374

GitHubd0n601/cve-2025-13374

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action

code-analysisexploitationpayload-generation+3
9 months ago
CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit preview

CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit

GitHubelsevar11/cve-2024-0670-checkmk-agent-local-privilege-escalation-exploit

This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for…

binary-exploitationeducationexploitation+4
39 months ago
CVE-2025-9816 preview

CVE-2025-9816

GitHubmonzaviman/cve-2025-9816

Proof of Concept for Stored-XSS on Vulnerable WP-Statistics Plugin known as CVE-2025-9816

exploitationpayload-generationpenetration-testing+3
9 months ago
CVE-2025-12189 preview

CVE-2025-12189

GitHubd0n601/cve-2025-12189

Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.10.1321 - Cross-Site Request Forgery to…

exploitationpayload-generationpenetration-testing+3
9 months ago
Kraken preview

Kraken

GitHubkraken-ng/kraken

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

command-and-controlpayload-generationred-teaming+1
5552 years ago
AlanFramework preview

AlanFramework

GitHubenkomio/alanframework

A C2 post-exploitation framework

command-and-controlencryption-decryption-toolslateral-movement+7
4862 years ago
commend_sqli preview

commend_sqli

GitHubjet-pentest/commend_sqli
exploitationpayload-generationpenetration-testing+2
2 years ago
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
3003 years ago
log4j-poc preview

log4j-poc

GitHubcyberxml/log4j-poc

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

educationexploitationlabs-practice+4
723 years ago
Loki.Rat preview

Loki.Rat

GitHubthegeekht/loki.rat

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

command-and-controldata-exfiltrationlateral-movement+6
763 years ago
Octopus preview

Octopus

GitHubmhaskar/octopus

Open source pre-operation C2 server based on python and powershell

command-and-controlencryption-decryption-toolsinformation-gathering+3
7635 years ago
Previous12Next