Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
NetExec preview

NetExec

GitHubpennyw0rth/netexec

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

command-and-controldatabase-securityexploitation+14
5.8k
3h 54m ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k2 days ago
CVE-2026-75604-poc preview

CVE-2026-75604-poc

GitHubrafabd1/cve-2026-75604-poc

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js apps, with callback-based command…

exploitationpenetration-testingremote-access-trojan+2
829 days ago
CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation preview

CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation

GitHubduyduongduyduong/cve-2024-4577-exploitation-asyncrat-deployment-dfir-investigation

Investigation of CVE-2024-4577 exploitation and AsyncRAT deployment with DFIR artifacts, IoCs, and detection guidance.

command-and-controldigital-forensicsexploitation+3
22 days ago
PSSW100AVB preview

PSSW100AVB

GitHubtihanyin/pssw100avb

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

ai-securitycommand-and-controlids-ips-evasion+5
1.4k3 months ago
CVE-2026-33725 preview

CVE-2026-33725

GitHubhakaioffsec/cve-2026-33725

Proof-of-concept exploit for CVE-2026-33725, achieving remote code execution and arbitrary file read via H2 JDBC INIT injection in Metabase…

exploitationpenetration-testingremote-access-trojan+2
254 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubinzegosec/cve-2026-23744

Exploit for MCPJam Inspector <=1.4.2 that triggers remote code execution via crafted HTTP requests, enabling unauthorized installation of MCP servers…

exploitationpenetration-testingremote-access-trojan+2
15 months ago
DuplexSpyCS preview

DuplexSpyCS

GitHubiss4cf0ng/duplexspycs

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

command-and-controleducationpayload-development+5
2226 months ago
CVE-2026-0770-PoC preview

CVE-2026-0770-PoC

GitHubaffix/cve-2026-0770-poc

Proof of Concept for CVE-2026-0770 - Langflow Remote Code Execution

exploitationpenetration-testingremote-access-trojan+2
66 months ago
DesckVB-RAT preview

DesckVB-RAT

GitHubshadowopcode/desckvb-rat

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

command-and-controldigital-forensicseducation+8
97 months ago
claude-poc preview

claude-poc

GitHubrootup/claude-poc

Claude Code Remote Code Execution

command-and-controlexploitationpayload-development+3
157 months ago
backdoors preview

backdoors

GitHubhackerhouse-opensource/backdoors

Tools for maintaining access to systems and proof-of-concept demonstrations.

command-and-controlpayload-developmentpersistence-mechanisms+3
1827 months ago
TelegramRAT preview

TelegramRAT

GitHubmachine1337/telegramrat

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions

command-and-controlinformation-gatheringpost-exploitation+3
45011 months ago
merlin preview

merlin

GitHubne0nd0g/merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

command-and-controldata-exfiltrationexploit-frameworks+10
5.6k1 year ago
kubesploit preview

kubesploit

GitHubcyberark/kubesploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

command-and-controlcontainer-escapecontainer-security+8
1.2k1 year ago
telegram-c2 preview

telegram-c2

GitHubtomiwa-ot/telegram-c2

Control a system remotely via telegram

command-and-controlinformation-gatheringpersistence-mechanisms+4
491 year ago
malvinci preview

malvinci

GitHubgsoffmarket/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controldata-exfiltrationpayload-development+3
591 year ago
Windows-X64-RAT preview

Windows-X64-RAT

GitHubmaorbuskila/windows-x64-rat

Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode…

binary-exploitationcommand-and-controleducation+5
22 years ago
Previous123Next