Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
92 results
MacShellSwift preview

MacShellSwift

GitHubcedowens/macshellswift

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

defensive-toolspenetration-testingpost-exploitation+2
124
5 years ago
PyHmmm preview

PyHmmm

GitHubcodextf2/pyhmmm

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

command-and-controleducationpayload-development+2
862 years ago
revshell preview

revshell

GitHubprodigiousmind/revshell

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

exploitationpayload-generationpenetration-testing+3
43 years ago
metasploitavevasion preview

metasploitavevasion

GitHubnccgroup/metasploitavevasion

Metasploit AV Evasion Tool

command-and-controlexploitationids-ips-evasion+4
25610 years ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Weaponized web shell

penetration-testingpost-exploitationprivilege-escalation+4
3.5k10 months ago
jsch preview

jsch

GitHubmwiede/jsch

fork of the popular jsch library

authentication-authorizationencryption-decryption-toolsnetwork-security+2
1.1k8 days ago
Peyara-FileUpload preview

Peyara-FileUpload

GitHubcapture0x/peyara-fileupload

Peyara Remote Mouse Unauthenticated Arbitrary File Upload

exploitationpayload-generationremote-access-tool+1
1 year ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubdinosn/cve-2026-34197

CVE-2026-34197 activemq PoC

exploitationpenetration-testingred-teaming+3
84 months ago
cve-2021-44228-log4shell_rce_reproduction preview

cve-2021-44228-log4shell_rce_reproduction

GitHubrazureink/cve-2021-44228-log4shell_rce_reproduction

CVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE

educationexploitationpayload-generation+3
27 days ago
CVE-2019-10758 preview

CVE-2019-10758

GitHublp008/cve-2019-10758

CVE-2019-10758

command-and-controlexploitationpayload-generation+2
56 years ago
CVE-2026-PoCs preview

CVE-2026-PoCs

GitHubsecurewithumer/cve-2026-pocs

A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.

curated-resourceseducationexploitation+5
351 month ago
Browser-C2 preview

Browser-C2

GitHub0x09al/browser-c2

Post Exploitation agent which uses a browser to do C2 operations.

command-and-controlpenetration-testingpost-exploitation+2
1048 years ago
EvilOSX preview

EvilOSX

GitHubcys3c/evilosx

A pure python, post-exploitation, remote administration tool (RAT) for macOS / OS X.

command-and-controlencryption-decryption-toolspersistence-mechanisms+2
519 years ago
RAT-via-Telegram preview

RAT-via-Telegram

GitHubdviros/rat-via-telegram

Windows Remote Post Breach Tool via Telegram

command-and-controldata-exfiltrationinformation-gathering+7
1358 years ago
PoshC2_Old preview

PoshC2_Old

GitHubnettitude/poshc2_old

Powershell C2 Server and Implants

command-and-controlexploit-frameworkslateral-movement+5
5756 years ago
Bella preview

Bella

GitHub00xglitch/bella

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

command-and-controldata-exfiltrationids-ips-evasion+8
2053 years ago
CVE-2020-5902-POC-EXP preview

CVE-2020-5902-POC-EXP

GitHublijiaxing1997/cve-2020-5902-poc-exp

批量扫描CVE-2020-5902,远程代码执行,已测试

exploitationpenetration-testingremote-access-tool+2
106 years ago
CVE-2019-0192 preview

CVE-2019-0192

GitHubmpgn/cve-2019-0192

RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl

exploitationpayload-developmentpenetration-testing+3
2087 years ago
Previous123456Next