Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
105 results
webhandler preview

webhandler

GitHublnxg33k/webhandler

Bash simulator to control a server using PHP system functions.

command-and-controlids-ips-evasionpayload-generation+3
100
5 years ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
38.9k17h 29m ago
BlackLotus preview

BlackLotus

GitHubldpreload/blacklotus

UEFI bootkit for Windows with Secure Boot bypass, kernel-level persistence, and encrypted HTTPS C2. Features HVCI/UAC bypass, API hooking, and…

command-and-controldefensive-toolsexploitation+8
2.2k2 years ago
b374k preview

b374k

GitHubb374k/b374k

Single-file PHP webshell providing remote file management, command execution, bind/reverse shell, database connectivity, and process control for…

command-and-controldatabase-securitypenetration-testing+2
2.7k3 years ago
WMImplant preview

WMImplant

GitHubredsiege/wmimplant

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

command-and-controlinformation-gatheringlateral-movement+3
8652 years ago
SharpWMI preview

SharpWMI

GitHubghostpack/sharpwmi

C# implementation of WMI for remote process creation, VBS execution, file upload, and system enumeration with alternate credential support and AMSI…

command-and-controlinformation-gatheringlateral-movement+5
7675 years ago
PCShare preview

PCShare

GitHubxdnice/pcshare

HTTP-based remote access tool with DLL injection, process hollowing, and system hooking for persistent control, screen monitoring, file exfiltration,…

command-and-controldata-exfiltrationlateral-movement+9
5699 years ago
paradoxiaRAT preview

paradoxiaRAT

GitHubquantumcore/paradoxiarat

Native Windows remote access tool with stealth client, reflective DLL injection, keylogger, Chrome password recovery, reverse shell, file system…

command-and-controlpassword-crackingpenetration-testing+4
8263 years ago
RSPET preview

RSPET

GitHubpanagiks/rspet

Python-based reverse shell with TLS encryption, file transfer, UDP flooding/spoofing, plugin system, and RESTful API for post-exploitation and red…

command-and-controlexploitationpayload-generation+4
2638 years ago
grc2 preview

grc2

GitHubandreiverse/grc2

Lightweight C2 framework written in Nim for generating implants, managing listeners, and executing tasks via TCP/HTTP with a loot system for…

command-and-controlpayload-generationred-teaming+1
3453 years ago
SirepRAT preview

SirepRAT

GitHubsafebreach-labs/sireprat

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

command-and-controlexploitationiot-security+4
3895 years ago
DarkAgent preview

DarkAgent

GitHubilikenwf/darkagent

Open-source Remote Administration Tool (RAT) providing remote system control, file management, and command execution for authorized penetration…

command-and-controlpenetration-testingpost-exploitation+3
14213 years ago
CVE-2019-0708-EXP-Windows preview

CVE-2019-0708-EXP-Windows

GitHubcbwang505/cve-2019-0708-exp-windows

Single-file Windows exploit for CVE-2019-0708 (BlueKeep) that executes a reverse shell with SYSTEM privileges via RDP, statically compiled with…

exploitationpayload-generationpenetration-testing+3
3176 years ago
pyrexecd preview

pyrexecd

GitHubeuske/pyrexecd

Standalone SSH server for Windows with pubkey authentication, clipboard sharing, and system tray integration. Supports remote command execution and…

authenticationremote-access-toolutilities-frameworks
2263 years ago
n00bRAT preview

n00bRAT

GitHubabhishekkr/n00brat

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

command-and-controleducationfingerprint-spoofing+5
1747 years ago
Nim-Reverse-Shell preview

Nim-Reverse-Shell

GitHubsn1r/nim-reverse-shell

A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell…

educationpayload-developmentpayload-generation+1
1243 years ago
CVE-2023-27532 preview

CVE-2023-27532

GitHubsfewer-r7/cve-2023-27532

Proof-of-concept exploit for CVE-2023-27532 that leaks plaintext credentials or executes remote commands with SYSTEM privileges on Veeam Backup &…

command-and-controlexploitationpenetration-testing+2
1133 years ago
BackDoorSim preview

BackDoorSim

GitHubhalildeniz/backdoorsim

Educational remote administration tool for learning RAT concepts, featuring file transfer, screenshot capture, system monitoring, and webcam access…

educationpenetration-testingpost-exploitation+2
1222 years ago
Previous123456Next