Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
92 results
Auto-PostXploit preview

Auto-PostXploit

GitHubbehzadmagzer/auto-postxploit

Windows Auto Post Exploitation - For ReD Team

information-gatheringpenetration-testingpost-exploitation+1
15
7 years ago
GC2-sheet preview

GC2-sheet

GitHubloociprian/gc2-sheet

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

command-and-controldata-exfiltrationmalware-analysis+2
6491 month ago
PingRAT preview

PingRAT

GitHubumutcamliyurt/pingrat

ICMP-based command-and-control tool that tunnels C2 traffic through firewalls using ping payloads, undetectable by most AV/EDR solutions.

command-and-controlpenetration-testingred-teaming+1
4713 months ago
RSPET preview

RSPET

GitHubpanagiks/rspet

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

command-and-controlexploitationpayload-generation+4
2638 years ago
grc2 preview

grc2

GitHubandreiverse/grc2

Lightweight C2 framework written in Nim for generating implants, managing listeners, and executing tasks via TCP/HTTP with a loot system for…

command-and-controlpayload-generationred-teaming+1
3453 years ago
sticky_keys_hunter preview

sticky_keys_hunter

GitHubztgrace/sticky_keys_hunter

A script to test an RDP host for sticky keys and utilman backdoor.

penetration-testingpost-exploitationremote-access-tool+1
2639 years ago
RAT-via-Telegram preview

RAT-via-Telegram

GitHubdviros/rat-via-telegram

Windows Remote Post Breach Tool via Telegram

command-and-controldata-exfiltrationinformation-gathering+7
1358 years ago
MacShellSwift preview

MacShellSwift

GitHubcedowens/macshellswift

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

defensive-toolspenetration-testingpost-exploitation+2
1245 years ago
Browser-C2 preview

Browser-C2

GitHub0x09al/browser-c2

Post Exploitation agent which uses a browser to do C2 operations.

command-and-controlpenetration-testingpost-exploitation+2
1048 years ago
PyHmmm preview

PyHmmm

GitHubcodextf2/pyhmmm

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

command-and-controleducationpayload-development+2
862 years ago
YAPS preview

YAPS

GitHubnickguitar/yaps

Yet Another PHP Shell - The most complete PHP reverse shell

command-and-controlexploitationinformation-gathering+7
844 years ago
CVE-2023-24489-ShareFile preview

CVE-2023-24489-ShareFile

GitHubadhikara13/cve-2023-24489-sharefile

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

command-and-controlexploitationpenetration-testing+3
133 years ago
CVE-2019-16278 preview

CVE-2019-16278

GitHubanubissec/cve-2019-16278

A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Simply takes a host and port that the web server is running on.

exploitationpenetration-testingremote-access-tool+2
86 years ago
revshell preview

revshell

GitHubprodigiousmind/revshell

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

exploitationpayload-generationpenetration-testing+3
43 years ago
CVE-2026-57517 preview

CVE-2026-57517

GitHubshinthink/cve-2026-57517

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

exploitationpayload-developmentpenetration-testing+4
11 month ago
paint2die preview

paint2die

GitHublucaskatashi/paint2die

Simplest and most reliable RichFaces Paint2DResource CVE-2018-12533 RF-14310 exploit PoC

exploitationpayload-generationpenetration-testing+3
18 months ago
CVE-2024-12252 preview

CVE-2024-12252

GitHubnxploited/cve-2024-12252

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2025-55182-Terminal preview

CVE-2025-55182-Terminal

GitHubmrsol0/cve-2025-55182-terminal

This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list

exploitationpayload-generationpenetration-testing+3
8 months ago
Previous123456Next