Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
hoaxshell preview

hoaxshell

GitHubt3l3machus/hoaxshell

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

command-and-controlexploitationpayload-generation+5
3.5k
1 year ago
CVE-2026-46368-OpenWrt-Exploit preview

CVE-2026-46368-OpenWrt-Exploit

GitHubiwallplace/cve-2026-46368-openwrt-exploit

Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)

command-and-controlexploitationpenetration-testing+3
2 months ago
Egress-Assess preview

Egress-Assess

GitHubredsiege/egress-assess

Multi-protocol data exfiltration testing tool that simulates real-world egress scenarios over FTP, HTTP, HTTPS, DNS, ICMP, SMB, SMTP, and SFTP to…

data-exfiltrationnetwork-securitypenetration-testing+1
7183 years ago
proxychains preview

proxychains

GitHubhaad/proxychains

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…

dns-analysisnetwork-securitypenetration-testing+1
7.9k2 years ago
Neton preview

Neton

GitHubaetsu/neton

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

educationinformation-gatheringmalware-analysis+1
1003 years ago
QuickResponseC2 preview

QuickResponseC2

GitHubkimd155/quickresponsec2

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…

command-and-controlpayload-generationpenetration-testing+2
543 months ago
Octopus preview

Octopus

GitHubmhaskar/octopus

Open source pre-operation C2 server based on python and powershell

command-and-controlencryption-decryption-toolsinformation-gathering+3
7635 years ago
sslsplit preview

sslsplit

GitHubdroe/sslsplit

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

encryption-decryption-toolsforensicsids-ips-evasion+5
1.9k10 months ago
DeimosC2 preview

DeimosC2

GitHubdeimosc2/deimosc2

DeimosC2 is a Golang command and control framework for post-exploitation.

command-and-controlexploit-frameworkspayload-generation+2
1.2k1 year ago
HRShell preview
Archived

HRShell

GitHubchrispetrou/hrshell

HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.

command-and-controlencryption-decryption-toolsexploitation+7
2484 years ago
C2concealer preview

C2concealer

GitHubredsiege/c2concealer

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…

command-and-controlpayload-generationpenetration-testing-frameworks+1
1.1k4 months ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
95819h 5m ago
GraphStrike preview

GraphStrike

GitHubredsiege/graphstrike

Cobalt Strike HTTPS beaconing over Microsoft Graph API

api-securitycloud-securitycommand-and-control+3
6372 years ago
HTTP-revshell preview

HTTP-revshell

GitHub3v4si0n/http-revshell

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

command-and-controlids-ips-evasionpayload-generation+4
5981 year ago
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
3003 years ago
sccm-http-looter preview

sccm-http-looter

GitHubbadsectorlabs/sccm-http-looter

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

data-exfiltrationinformation-gatheringmisconfiguration+3
2161 year ago
Reverse_HTTPS_Bot preview

Reverse_HTTPS_Bot

GitHubahhh/reverse_https_bot

A python based https remote access trojan for penetration testing

command-and-controlpayload-developmentpenetration-testing+3
8410 years ago
PULSE-C2 preview

PULSE-C2

GitHub28zaaky/pulse-c2

HTTPS C&C Framework with encrypted beacons, web dashboard, and Windows agent.

command-and-controlencryption-decryption-toolspayload-development+2
536 months ago
Previous12Next