Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
60 results
Mythic-Macro-Generator preview

Mythic-Macro-Generator

GitHubcedowens/mythic-macro-generator

Python3 script to generate a macro to launch a Mythic payload. Author: Cedric Owens

command-and-controlexploit-frameworkspayload-development+4
47
5 years ago
phantom-keylogger preview

phantom-keylogger

GitHubmattiaalessi/phantom-keylogger

Phantom Keylogger is an advanced, stealth-enabled keystroke and visual intelligence gathering system.

command-and-controldata-exfiltrationids-ips-evasion+6
779 months ago
SMBRat preview

SMBRat

GitHuboperatorequals/smbrat

A Windows Remote Administration Tool in Visual Basic with UNC paths

command-and-controlexploitationlateral-movement+8
227 years ago
C2 preview

C2

GitHubet0x/c2

Methods of C2

command-and-controlpayload-developmentpayload-generation+3
2111 years ago
RedbloodC2 preview

RedbloodC2

GitHubkira2040k/redbloodc2

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

command-and-controldata-exfiltrationencryption-decryption-tools+5
293 years ago
MS-MSDT-Office-RCE-Follina preview

MS-MSDT-Office-RCE-Follina

GitHub0xflagplz/ms-msdt-office-rce-follina

CVE-2022-30190 | MS-MSDT Follina One Click

command-and-controlexploitationlateral-movement+3
204 years ago
hideNsneak preview

hideNsneak

GitHubrmikehodges/hidensneak

a CLI for ephemeral penetration testing

cloud-securitycommand-and-controlpayload-generation+5
186 years ago
Malicious-MCP preview

Malicious-MCP

GitHubquinnbast/malicious-mcp

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

ai-securitycommand-and-controldata-exfiltration+8
85 months ago
SignHere preview

SignHere

GitHubretr0-code/signhere

SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.

command-and-controlexploitationpayload-generation+3
65 years ago
CVE-2021-28079 preview

CVE-2021-28079

GitHubg33xter/cve-2021-28079

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

command-and-controlexploitationpayload-development+3
44 years ago
git-clean-filter preview

git-clean-filter

GitHubrootup/git-clean-filter

This is a proof-of-work for abusing git's clean filter against IDEs & Sublime.

command-and-controlids-ips-evasionpersistence-mechanisms+3
33 months ago
Xworm RAT preview

Xworm RAT

GitLabmanturever/xworm-rat

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

command-and-controlcryptographydata-exfiltration+8
34 months ago
CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval- preview

CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval-

GitHubgeorge0papasotiriou/cve-2026-22005-oauth-2.0-device-code-phishing-short-interval-

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

authentication-authorizationeducationexploitation+4
1 month ago
Amaranth-Project preview

Amaranth-Project

GitHublewis-ricardo/amaranth-project

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

command-and-controleducationexploitation+6
3 months ago
APT-Backpack preview

APT-Backpack

GitHub34zy/apt-backpack

cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084,…

command-and-controldata-exfiltrationexploitation+6
33 years ago
CVE-2017-8759 preview

CVE-2017-8759

GitHubsythass/cve-2017-8759

CVE-2017-8759

command-and-controlexploitationpayload-generation+2
9 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
CVE-2025-50154-Aggressor-Script preview

CVE-2025-50154-Aggressor-Script

GitHubash1996x/cve-2025-50154-aggressor-script

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

command-and-controlctfeducation+9
11 year ago
Previous1234Next