Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1269 results
AllHackingTools preview

AllHackingTools

GitHubmishakorzik/allhackingtools

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

crawlerexploitationhash-analysis+8
6.1k
9 months ago
EQGRP preview

EQGRP

GitHubx0rz/eqgrp

Collection of leaked NSA Equation Group exploits, backdoors, and tools for post-exploitation, privilege escalation, and command-and-control across…

command-and-controldata-exfiltrationexploitation+8
4.2k9 years ago
php-reverse-shell preview

php-reverse-shell

GitHubpentestmonkey/php-reverse-shell

PHP script that establishes a reverse shell from a target server to the attacker's machine, enabling remote command execution and post-exploitation…

exploitationpenetration-testingpost-exploitation+2
2.9k2 years ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Stealthy PHP web shell for penetration testing and post-exploitation with remote shell, file operations, privilege escalation, and reconnaissance…

penetration-testingpost-exploitationprivilege-escalation+4
3.5k10 months ago
b374k preview

b374k

GitHubb374k/b374k

Single-file PHP webshell providing remote file management, command execution, bind/reverse shell, database connectivity, and process control for…

command-and-controldatabase-securitypenetration-testing+2
2.7k3 years ago
p0wny-shell preview

p0wny-shell

GitHubflozz/p0wny-shell

Single-file PHP web shell for remote command execution with file upload/download and command history, designed for penetration testing of PHP…

penetration-testingremote-access-toolweb-application-exploitation
2.9k1 year ago
PocList preview

PocList

GitHub1n7erface/poclist

Vulnerability-specific PoC scripts for discovering and exploiting RCE, SQLi, XXE, SSRF, and unauthorized-access flaws in enterprise web apps and…

exploitationinformation-gatheringpenetration-testing+3
1.1k3 years ago
webshells preview

webshells

GitHubblackarch/webshells

Curated collection of webshell scripts for web server remote access and command execution, supporting multiple languages including PHP, ASP, and JSP.

payload-generationpenetration-testingpost-exploitation+3
1.0k3 years ago
wwwolf-php-webshell preview

wwwolf-php-webshell

GitHubwhitewinterwolf/wwwolf-php-webshell

Minimal PHP web shell with password-protected remote command execution, file upload/fetch, for penetration testing on Unix and Windows targets.

exploitationpenetration-testingpost-exploitation+2
8018 years ago
PyShell preview

PyShell

GitHubjoelgmsec/pyshell

Multi-platform Python webshell providing remote shell access on web servers with command history, file upload/download, and directory traversal…

payload-generationpenetration-testingremote-access-tool+1
31920 days ago
cve-2019-19781 preview

cve-2019-19781

GitHubtrustedsec/cve-2019-19781

This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.

exploitationinformation-gatheringpenetration-testing+3
5736 years ago
nano preview

nano

GitHubs0md3v/nano

Stealthy, code-golfed PHP webshell family with authentication support and undetectable payload delivery for remote command execution via HTTP.

command-and-controlpayload-generationpenetration-testing+3
4496 years ago
CVE-2017-12617 preview

CVE-2017-12617

GitHubcyberheartmi9/cve-2017-12617

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution

exploitationpayload-generationpenetration-testing+3
3998 years ago
DAws preview

DAws

GitHubdotcppfile/daws

PHP-based web shell with automated WAF/IPS evasion, CGI shell dropping, SSH key persistence, Shellshock exploitation, XOR-encrypted communication,…

ids-ips-evasionpayload-generationpenetration-testing+6
5809 years ago
quasibot preview

quasibot

GitHubsmaash/quasibot

complex webshell manager, quasi-http botnet.

command-and-controlexploitationinformation-gathering+6
28411 years ago
mec preview

mec

GitHubjm33-m0/mec

Mass exploitation console with built-in exploits, SSH brute-forcer, and multi-source host reconnaissance (ZoomEye, Censys, Baidu) for automated…

exploitationexploit-frameworksinformation-gathering+5
6154 years ago
JSshell preview

JSshell

GitHubshelld3v/jsshell

JavaScript reverse shell for executing JS code remotely via blind XSS. Generates payloads, listens for connections, and executes commands in the…

payload-generationpenetration-testingremote-access-tool+1
6313 years ago
php-reverse-shell preview

php-reverse-shell

GitHubivan-sincek/php-reverse-shell

PHP shells that work on Linux OS, macOS, and Windows OS.

educationexploitationpenetration-testing+4
5725 months ago
Previous12…71Next