Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1413 results
Striker preview

Striker

GitHub4g3nt47/striker

Multi-operator C2 framework with native C and Python agents, HTTP(S) channels, asynchronous tasking, and a reactive web UI for red team operations.

command-and-controlpayload-generationred-teaming+1
300
3 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubmr-r00t11/cve-2024-23692

Rejetto HFS (HTTP File Server) is a simple web file server that facilitates file sharing over a network or the internet.

exploitationpayload-generationpenetration-testing+4
2 years ago
SMShell preview

SMShell

GitHubpersistent-security/smshell

PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers

command-and-controlexploitationmobile-security+3
3723 years ago
c2s preview

c2s

GitHubj3ssie/c2s

Command and Control server on Slack

command-and-controlpenetration-testingpost-exploitation+2
307 years ago
tinyshell preview

tinyshell

GitHubzux0x3a/tinyshell

Small PHP shell, Controlled by Python Client , connecting over protocol method

command-and-controlpayload-generationremote-access-tool+1
67 years ago
mqxss preview

mqxss

GitHubgrampae/mqxss

Hooked browser communication over MQTT

command-and-controlinformation-gatheringpayload-generation+4
82 years ago
Exploits_CVE-2019-19781 preview

Exploits_CVE-2019-19781

GitHubunknowndevice64/exploits_cve-2019-19781

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781). Executes arbitrary commands on vulnerable…

exploitationpenetration-testingred-teaming+3
46 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubj4ck3lsyn-gen2/cve-2025-55182

A simple toolkit to validate, exploit & gain an interactive shell via the react2Shell Next.js RCE.

command-and-controleducationexploitation+5
5 months ago
php_reverse_shell preview

php_reverse_shell

GitHubh3x0v3rl0rd/php_reverse_shell

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

command-and-controlpenetration-testingpost-exploitation+3
5 years ago
-CVE-2017-7494-Samba-Exploit-POC preview

-CVE-2017-7494-Samba-Exploit-POC

GitHubadjaliya/-cve-2017-7494-samba-exploit-poc

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable…

exploitationpenetration-testingred-teaming+3
4 years ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubnotdls/cve-2022-36804

A real exploit for BitBucket RCE CVE-2022-36804

exploitationpenetration-testingred-teaming+3
352 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubgunzf0x/cve-2021-41773

Python-based proof-of-concept exploit for CVE-2021-41773, enabling remote code execution on Apache 2.4.49 servers with custom command and port…

exploitationpenetration-testingred-teaming+3
11 months ago
log4j-vulnerability preview

log4j-vulnerability

GitHubmarceloleite2604/log4j-vulnerability

Presents how to exploit CVE-2021-44228 vulnerability.

command-and-controleducationexploitation+5
14 years ago
CVE-2018-1000861 preview

CVE-2018-1000861

GitHubsmokeintheshell/cve-2018-1000861

CVE-2018-1000861 Exploit

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2021-26814 preview

CVE-2021-26814

GitHubwickddavid/cve-2021-26814

A simple python PoC to exploit CVE-2021-26814 and gain RCE on Wazuh Manager (v.4.0.0-4.0.3) through the API service.

exploitationpenetration-testingremote-access-tool+2
45 years ago
emp3r0r preview

emp3r0r

GitHubjm33-m0/emp3r0r

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

anti-botcommand-and-controlids-ips-evasion+10
1.7k1 day ago
SlackShell preview

SlackShell

GitHubbkup/slackshell

PowerShell to Slack C2

command-and-controlpayload-developmentpenetration-testing+3
1078 years ago
CVE-2021-26814 preview

CVE-2021-26814

GitHubcys4srl/cve-2021-26814

PoC of CVE-2021-26814

exploitationpenetration-testingremote-access-tool+2
25 years ago
Previous12…79Next