Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
386 results
Loki.Rat preview

Loki.Rat

GitHubthegeekht/loki.rat

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

command-and-controldata-exfiltrationlateral-movement+6
76
3 years ago
ZeroRAT preview

ZeroRAT

GitHub5alt/zerorat

ZeroRAT是一款windows上的一句话远控

command-and-controldata-exfiltrationexploitation+9
6310 years ago
Phoenix-Framework preview

Phoenix-Framework

GitHubxm0kht4r/phoenix-framework

Post-exploitation framework that abuses trusted sites like Telegram and Discord for C2.

command-and-controldata-exfiltrationpayload-development+5
713 months ago
w11_shadow_copies preview

w11_shadow_copies

GitHubricardojoserf/w11_shadow_copies

Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11

data-exfiltrationexploitationlateral-movement+5
846 months ago
reave preview

reave

GitHubpsmths/reave

WIP Post-exploitation framework tailored for hypervisors.

command-and-controldata-exfiltrationexploit-frameworks+8
502 years ago
Schwarze-Sonne-RAT preview

Schwarze-Sonne-RAT

GitHubmwsrc/schwarze-sonne-rat

SS-RAT (Schwarze-Sonne-Remote-Access-Trojan)

command-and-controldata-exfiltrationlateral-movement+6
299 years ago
teletunnel preview

teletunnel

GitHubmhdgning131/teletunnel

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

command-and-controldata-exfiltrationids-ips-evasion+7
444 months ago
Invoke-HiveNightmare preview

Invoke-HiveNightmare

GitHubwiredpulse/invoke-hivenightmare

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version…

data-exfiltrationexploitationpost-exploitation+2
355 years ago
bat preview

bat

GitHubrhzv0/bat
command-and-controldata-exfiltrationlateral-movement+5
363 months ago
sigma-ai preview

sigma-ai

GitHubagentshield-ai/sigma-ai

Sigma detection rules for AI agent security monitoring

ai-securityanomaly-detectiondata-exfiltration+8
1524 days ago
XeytanWin32-RAT preview

XeytanWin32-RAT

GitHubmelardev/xeytanwin32-rat

WORK IN PROGRESS. RAT written in C++ using Win32 API

command-and-controldata-exfiltrationexploitation+8
206 years ago
DeepTrap preview

DeepTrap

GitHubzjuicsr/deeptrap

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

adversarial-attackai-securitycommand-and-control+8
103 months ago
Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis preview

Agent-Tesla-APC-Injection-Token-Manipulation-Registry-Persistence-Analysis

GitHubkaandemir993/agent-tesla-apc-injection-token-manipulation-registry-persistence-analysis

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

binary-analysisdata-exfiltrationeducation+4
313 days ago
wp2shell preview

wp2shell

GitHubiqbalx7/wp2shell

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

api-securityexploitationpassword-cracking+4
1 month ago
CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open preview

CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open

GitHubgeorge0papasotiriou/cve-2026-11111-toctou-in-file-permission-check-before-open
data-exfiltrationeducationexploitation+4
17 days ago
tesla-security-research preview

tesla-security-research

GitHubanalyticeth/tesla-security-research

Vulnerability research on Tesla Model 3/Y infotainment systems. 6 vulnerabilities, 4 CVEs (CVE-2022-42005 through CVE-2022-42008). Root shell,…

command-and-controldata-exfiltrationeducation+7
52 months ago
glass-cage-i18-2025-24085-and-cve-2025-24201 preview

glass-cage-i18-2025-24085-and-cve-2025-24201

GitHub5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

binary-exploitationdata-exfiltrationeducation+9
511 months ago
mailorder preview

mailorder

GitHubmonoxgas/mailorder

Nalpeiron Licensing Service (NLSSRV32) arbitrary disk read [CVE-2019-19315]

binary-exploitationdata-exfiltrationexploitation+2
46 years ago
Previous1…19202122Next