Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
999 results
CVE-2023-41425-RCE-WonderCMS-4.3.2 preview

CVE-2023-41425-RCE-WonderCMS-4.3.2

GitHubtea-on/cve-2023-41425-rce-wondercms-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

educationexploitationpayload-generation+5
8
1 year ago
ranger preview

ranger

GitHubfunkandwagnalls/ranger

A tool for security professionals to access and interact with remote Microsoft Windows based systems.

command-and-controlexploitationlateral-movement+3
4318 years ago
Brosec preview

Brosec

GitHubgabemarshall/brosec

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

encryption-decryption-toolsexploitationinformation-gathering+7
3505 years ago
JWTweak preview

JWTweak

GitHubrishuranjanofficial/jwtweak

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

authenticationcryptographypayload-generation+3
1031 month ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubim2sinister/cve-2021-41773
educationexploitationpayload-generation+3
11 month ago
boopkit preview

boopkit

GitHubkrisnova/boopkit

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

command-and-controlexploitationids-ips-evasion+6
1.7k3 years ago
Octopus preview

Octopus

GitHubmhaskar/octopus

Open source pre-operation C2 server based on python and powershell

command-and-controlencryption-decryption-toolsinformation-gathering+3
7635 years ago
RSPET preview

RSPET

GitHubpanagiks/rspet

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

command-and-controlexploitationpayload-generation+4
2638 years ago
Shelly preview

Shelly

GitHubtegal1337/shelly

Simple Backdoor Manager with Python (based on weevely)

payload-generationpenetration-testingremote-access-tool+1
961 year ago
Lilith preview

Lilith

GitHubwerkamsus/lilith

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

command-and-controlpayload-generationpenetration-testing+4
7506 years ago
py3webfuzz preview

py3webfuzz

GitHubjangelesg/py3webfuzz

A Python3 module to assist in fuzzing web applications

fuzzingpayload-generationpenetration-testing+2
572 years ago
SimpleRemoter preview

SimpleRemoter

GitHubyuanyuanxiang/simpleremoter

A remote control program based on Gh0st: 实现了终端管理、进程管理、窗口管理、远程桌面、文件管理、语音管理、视频管理、服务管理、注册表管理等功能,优化全部代码及整理排版,修复内存泄漏缺陷,程序运行稳定。项目代码仅限于学习和交流用途。

command-and-controleducationlateral-movement+6
1.3k3 months ago
Powershell-RAT preview

Powershell-RAT

GitHubviralmaniar/powershell-rat

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

data-exfiltrationeducationpayload-generation+4
1.2k6 years ago
bad_ducky preview

bad_ducky

GitHubmharjac/bad_ducky

Rubber Ducky compatible clone based on CJMCU BadUSB HW.

hardware-hackingids-ips-evasionimpersonation-tools+5
3018 years ago
Ares preview

Ares

GitHubcerbersec/ares

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

binary-analysisdefensive-toolsencryption-decryption-tools+7
3374 years ago
Excalibur preview

Excalibur

GitHubdviros/excalibur

Excalibur is an Eternalblue exploit payload based "Powershell" for the Bashbunny project.

educationexploitationexploit-frameworks+9
1337 years ago
sshimpanzee preview

sshimpanzee

GitHublexfo/sshimpanzee

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

command-and-controldns-analysisnetwork-security+4
2941 year ago
peCloakCapstone preview

peCloakCapstone

GitHubv-p-b/pecloakcapstone

Platform independent peCloak fork based on Capstone

binary-analysisids-ips-evasionmalware-analysis+2
11011 years ago
Previous12…56Next