Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
ImageTragick-CVE-2016-3714-RShell preview

ImageTragick-CVE-2016-3714-RShell

GitHubjpeanut/imagetragick-cve-2016-3714-rshell

Proof-of-concept exploit scripts for CVE-2016-3714 (ImageTragick) using MVG/SVG files to deliver reverse shells via bash, nc, and PHP for ethical…

exploitationpayload-generationpenetration-testing+3
18
10 years ago
OffensivePipeline preview

OffensivePipeline

GitHubaetsu/offensivepipeline

OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team exercises.

ids-ips-evasionpayload-generationred-teaming+1
8202 years ago
pyMalleableC2 preview

pyMalleableC2

GitHubbyt3bl33d3r/pymalleablec2

Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.

command-and-controlpayload-developmentred-teaming+1
2902 months ago
SharpRDP preview

SharpRDP

GitHub0xthirteen/sharprdp

Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

authenticationlateral-movementpenetration-testing+2
1.2k27 days ago
sshhipot preview

sshhipot

GitHubmagisterquis/sshhipot

High-interaction MitM SSH honeypot

defensive-toolsnetwork-securitypenetration-testing+1
1758 years ago
pentest_teamcity preview

pentest_teamcity

GitHubkacperszurek/pentest_teamcity

Pentest TeamCity using Metasploit

exploit-frameworkspayload-generationpenetration-testing+3
458 years ago
CcmMessagingBackdoor preview

CcmMessagingBackdoor

GitHubsynacktiv/ccmmessagingbackdoor

Proof-of-concept backdoor for SCCM Management Point using rogue COM service for persistent remote command execution as SYSTEM.

command-and-controlpayload-developmentpersistence-mechanisms+3
191 year ago
CVE-2021-4034-Rust preview

CVE-2021-4034-Rust

GitHubdeoxykev/cve-2021-4034-rust

Rust implementation of the CVE-2021-4034 polkit pkexec local privilege escalation exploit, with build instructions and detection considerations.

binary-exploitationexploitationexploit-frameworks+3
24 years ago
pentest-ai-agents preview

pentest-ai-agents

GitHub0xsteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

ai-securitycloud-securityeducation+8
2.2k14 days ago
DumpsterFire preview

DumpsterFire

GitHubtrycatchhcf/dumpsterfire

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…

defensive-toolseducationincident-response+3
1.0k6 years ago
rinhit preview

rinhit

GitLabtoxy4ny/rinhit

Collects macOS and iOS artifacts to build timelines of network activity, cross-device identity, and physical location correlation for reconnaissance…

bluetooth-securitydigital-forensicsinformation-gathering+6
6 days ago
unleashed-firmware preview

unleashed-firmware

GitHubdarkflippers/unleashed-firmware

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

embedded-systems-securityfuzzinghardware-hacking+7
22.1k1 day ago
c2s preview

c2s

GitHubj3ssie/c2s

Command and Control server on Slack

command-and-controlpenetration-testingpost-exploitation+2
307 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubhycheng15/cve-2022-30190

Python-based exploit for CVE-2022-30190 (Follina) with environment setup and malicious document generation for educational penetration testing.

educationexploitationpayload-generation+3
12 years ago
outis preview

outis

GitHubsyss-research/outis

outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms…

command-and-controldns-analysispayload-generation+3
1268 years ago
CVE-2018-5353 preview

CVE-2018-5353

GitHubmissing0x00/cve-2018-5353

CVE-2018-5353

exploitationpenetration-testingprivilege-escalation+3
5 years ago
DaaC2 preview

DaaC2

GitHubcrawl3r/daac2

Discord as a C2

command-and-controlpayload-generationred-teaming+1
515 years ago
SourcePoint preview

SourcePoint

GitHubtylous/sourcepoint

Polymorphic C2 profile generator for Cobalt Strike that automates creation of evasive beacon configurations with randomized options for HTTP, DNS,…

command-and-controlexploit-frameworkspayload-generation+1
1.2k1 year ago
Previous123Next