Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
CVE-2026-24061 preview

CVE-2026-24061

GitHubobrunolima1910/cve-2026-24061

🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.

authenticationeducationexploitation+3
12h 1m ago
lamda preview

lamda

GitHubfirerpa/lamda

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

android-securitydynamic-analysis-sandboxingeducation+8
8.2k4 days ago
porterminal preview

porterminal

GitHublyehe/porterminal

Quick n' dirty web/mcp terminal tunneling your phone & pc

command-and-controlpenetration-testingred-teaming+3
2977 days ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
20821 days ago
EvilAhenk preview

EvilAhenk

GitHubjackalkarlos/evilahenk

CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod…

command-and-controlexploitationlateral-movement+7
21 month ago
grr preview

grr

GitHubgoogle/grr

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

digital-forensicsdisk-forensicsforensics+4
5.1k3 months ago
ReverseSocks5 preview

ReverseSocks5

GitHubacebond/reversesocks5

Single executable reverse SOCKS5 proxy written in Golang.

penetration-testingpost-exploitationred-teaming+1
1574 months ago
ligolo-iwa preview

ligolo-iwa

GitHubnicocha30/ligolo-iwa

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

lateral-movementpenetration-testingred-teaming+2
1354 months ago
GeckoDroid preview

GeckoDroid

GitHubblacksnufkin/geckodroid

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

android-securitycommand-and-controlmobile-security+4
385 months ago
hermes preview
Archived

hermes

GitHub0xbbuddha/hermes

A Python agent targeting Linux for Mythic C2

command-and-controlencryption-decryption-toolslateral-movement+6
185 months ago
wardgate preview

wardgate

GitHubwardgate/wardgate

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

api-securityauthentication-authorizationcloud-security+8
1365 months ago
PULSE-C2 preview

PULSE-C2

GitHub28zaaky/pulse-c2

HTTPS C&C Framework with encrypted beacons, web dashboard, and Windows agent.

command-and-controlencryption-decryption-toolspayload-development+2
536 months ago
chisel-ng preview

chisel-ng

GitHubnullsection/chisel-ng

Chisel new generation, written in rust. SSH under WSS with some customization.

command-and-controlids-ips-evasionlateral-movement+5
1366 months ago
connectwise-automate-AiTM-rce preview

connectwise-automate-AiTM-rce

GitHubsynap5e/connectwise-automate-aitm-rce

Writeup and code for CVE-2025-11492, CVE-2025-11493 - RCE in ConnctWise Automate RMM via Adversary-in-the-Middle

command-and-controleducationexploitation+8
19 months ago
thanatos preview

thanatos

GitHubmythicagents/thanatos

Mythic C2 agent targeting Linux and Windows hosts written in Rust

command-and-controlexploit-frameworkslateral-movement+4
40811 months ago
CVE-2025-27480 preview

CVE-2025-27480

GitHubmrk336/cve-2025-27480

CVE-2025-27480 exposes a buffer overflow in OpenSSH 8.9p1 via a malformed SSH_USERAUTH packet. Attackers can inject shellcode and gain SYSTEM-level…

binary-exploitationeducationexploitation+5
11 months ago
RingReaper preview

RingReaper

GitHubmatheuzsecurity/ringreaper

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

adversarial-attackcommand-and-controldata-exfiltration+5
38411 months ago
CVE-2024-49369 preview

CVE-2024-49369

GitHubquantum-sicarius/cve-2024-49369
command-and-controlexploitationinformation-gathering+3
20 years ago
Previous12Next