Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
CVE-2026-65400 preview

CVE-2026-65400

GitHubhorkimhab/cve-2026-65400

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

authenticationeducationexploitation+4
1
3 days ago
RPC-Backdoor preview

RPC-Backdoor

GitHubeladshamir/rpc-backdoor

A basic emulation of an "RPC Backdoor"

command-and-controllateral-movementpost-exploitation+3
2413 years ago
aardwolf preview

aardwolf

GitHubskelsec/aardwolf

Asynchronous RDP client for Python (headless)

authenticationinformation-gatheringlateral-movement+5
2387 days ago
gopher47 preview

gopher47

GitHuban00brektn/gopher47

A third-party Gopher Assassin for the Havoc Framework.

command-and-controlpenetration-testingport-scanning+4
442 years ago
Lastenzug preview

Lastenzug

GitHubps1337/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

ids-ips-evasionpayload-developmentpost-exploitation+3
264 years ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1622 years ago
tap preview

tap

GitHubtrustedsec/tap

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

command-and-controlpenetration-testing-frameworkspersistence-mechanisms+3
5043 years ago
voron-crypto preview

voron-crypto

GitHubsoftdeadlock/voron-crypto

Voron messenger crypto/protocol library (X3DH-lite + Double Ratchet, group sender-keys, onion transport) — external review requested

command-and-controlcryptographyencryption-decryption-tools+3
11 month ago
sshuttle preview

sshuttle

GitHubapenwarr/sshuttle

Wrong project! You should head over to http://github.com/sshuttle/sshuttle

network-securitypenetration-testingred-teaming+2
8.9k8 years ago
DarkAgent preview

DarkAgent

GitHubilikenwf/darkagent

DarkAgent Remote Administration Tool RAT by DragonHunter

command-and-controlpenetration-testingpost-exploitation+3
14213 years ago
XeytanWin32-RAT preview

XeytanWin32-RAT

GitHubmelardev/xeytanwin32-rat

WORK IN PROGRESS. RAT written in C++ using Win32 API

command-and-controldata-exfiltrationexploitation+8
206 years ago
XeytanWxCpp-RAT preview

XeytanWxCpp-RAT

GitHubmelardev/xeytanwxcpp-rat

Work in Progress. RAT written in C++ using wxWidgets

command-and-controlinformation-gatheringpayload-development+3
116 years ago
D-RAT_VB.NET_MySQL_PHP preview

D-RAT_VB.NET_MySQL_PHP

GitHubmr-wolf-gb/d-rat_vb.net_mysql_php

D-RAT [VB.NET]+[MySQL]+[PHP]

command-and-controlpayload-developmentpenetration-testing+3
146 years ago
rdroid preview

rdroid

GitHubhuntoai/rdroid

[Android RAT] Remotely manage your android phone using PHP Interface

android-securitycommand-and-controldata-exfiltration+3
2478 years ago
HFS_EXPLOIT_PROJECT preview

HFS_EXPLOIT_PROJECT

GitHubsage954526/hfs_exploit_project

Metasploit RCE on HFS 2.3 - CVE-2014-62

educationexploit-frameworkspenetration-testing+3
1 year ago
CVE-2020-0796-SMBGhost-Exploit-Demo preview

CVE-2020-0796-SMBGhost-Exploit-Demo

GitHubtdevworks/cve-2020-0796-smbghost-exploit-demo
binary-exploitationeducationexploitation+5
1 year ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhorkimhab/cve-2026-20253

CVE-2026-20253 - Splunk Enterprise

educationexploitationpenetration-testing+3
2 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsubhdotsol/cve-2025-55182

This project provides a fully functional demonstration of CVE-2025-55182 (React2Shell) - a critical Remote Code Execution vulnerability in React…

command-and-controleducationexploitation+5
28 months ago
Previous1234Next