Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
Koi preview

Koi

GitHubb3rt1ng/koi

Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

command-and-controlids-ips-evasionlateral-movement+9
27
6 days ago
CVE-2025-59287 preview

CVE-2025-59287

GitHubgarvitv14/cve-2025-59287

Automated exploit for CVE-2025-59287, an unauthenticated RCE in WSUS, featuring payload generation, reverse shell listener, and AES encryption with…

command-and-controlexploitationpayload-generation+4
1611 months ago
Lastenzug preview

Lastenzug

GitHubps1337/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

ids-ips-evasionpayload-developmentpost-exploitation+3
264 years ago
OffensiveLua preview

OffensiveLua

GitHubhackerhouse-opensource/offensivelua

Offensive Lua.

ids-ips-evasionpassword-attackspayload-development+6
2258 months ago
WAREED-DNS-C2 preview

WAREED-DNS-C2

GitHubfaisal-p27/wareed-dns-c2

DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

command-and-controlids-ips-evasionpayload-development+3
1481 year ago
phantap preview

phantap

GitHubnccgroup/phantap

Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams

ids-ips-evasionlateral-movementnetwork-mapping+4
6250 years ago
SocksOverRDP preview

SocksOverRDP

GitHubnccgroup/socksoverrdp

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

ids-ips-evasionlateral-movementpenetration-testing+3
1.3k3 years ago
modsecurity-backdoor preview

modsecurity-backdoor

GitHubazurit/modsecurity-backdoor

This is a proof-of-concept of malicious software running inside of ModSecurity WAF.

command-and-controlids-ips-evasionpost-exploitation+3
341 year ago
webhandler preview

webhandler

GitHublnxg33k/webhandler

Bash simulator to control a server using PHP system functions.

command-and-controlids-ips-evasionpayload-generation+3
1005 years ago
android-c-sharp-rat-server preview

android-c-sharp-rat-server

GitHubadvancedhacker101/android-c-sharp-rat-server

This is a plugin for the c# R.A.T server providing extension to android based phone systems

android-securitycommand-and-controldata-exfiltration+3
208 years ago
BlackHole preview

BlackHole

GitHubhussein-aitlahcen/blackhole

C# RAT (Remote Administration Tool)

command-and-controleducationpayload-development+5
3029 years ago
openssh-cve-2024-6387.sh preview

openssh-cve-2024-6387.sh

GitHubrumochnaya/openssh-cve-2024-6387.sh

openssh-cve-2024-6387.sh

configuration-auditingexploitationincident-response+3
12 years ago
CVE-2026-54424 preview

CVE-2026-54424

GitHubtomadimitrie/cve-2026-54424

Exploiting Parsec for Windows to gain SYSTEM privileges

binary-exploitationcommand-and-controlexploitation+5
3 months ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
File-Tunnel preview

File-Tunnel

GitHubfiddyschmitt/file-tunnel

Tunnel TCP connections through a file

ids-ips-evasionlateral-movementnetwork-mapping+3
1.1k1 month ago
CVE-2023-50564 preview

CVE-2023-50564

GitHubmrterrestrial/cve-2023-50564

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2022-22029-NFS-Server- preview

CVE-2022-22029-NFS-Server-

GitHubmchoudhary15/cve-2022-22029-nfs-server-

Proof-of-concept exploit for CVE-2022-22029, a Windows NFS remote code execution vulnerability. Includes PowerShell commands to disable NFSV3 as a…

exploitationnetwork-securitypenetration-testing+2
14 years ago
lamda preview

lamda

GitHubfirerpa/lamda

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

android-securitydynamic-analysis-sandboxingeducation+8
8.5k9 days ago
Previous123Next