Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
156 results
livewire-honeypot preview

livewire-honeypot

GitHubhelgesverre/livewire-honeypot

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

command-and-controldynamic-analysis-sandboxingexploitation+6
6
4 months ago
overload preview
Archived

overload

GitHubgoncalopolido/overload

A network stress testing tool for simulating high traffic loads.

network-securitypenetration-testingred-teaming+2
4333 months ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
flask_heroku_redirector preview

flask_heroku_redirector

GitHubkillswitch-gui/flask_heroku_redirector

flask heroku C2 redirector template

cloud-securitycommand-and-controlpenetration-testing+3
119 years ago
flask_pythonanywhere_redirector preview

flask_pythonanywhere_redirector

GitHubkillswitch-gui/flask_pythonanywhere_redirector

flask pythonanywhere C2 redirector template

command-and-controlpayload-developmentpenetration-testing+2
89 years ago
flask_appengine_redirector preview

flask_appengine_redirector

GitHubkillswitch-gui/flask_appengine_redirector

Google App Engine Flask C2 redirector

cloud-securitycommand-and-controlpenetration-testing+2
89 years ago
APT-Individual-Combat-Guide preview

APT-Individual-Combat-Guide

GitHubghostwolflab/apt-individual-combat-guide

Educational guide and code repository for understanding APT attack techniques, covering reconnaissance, web and service exploitation, trojans, C2,…

command-and-controleducationexploitation+7
11210 months ago
RedDrop preview

RedDrop

GitHubcyberbutler/reddrop

Python Flask web server for capturing, processing, and logging encoded/encrypted payloads and tar archives, designed for penetration testers and red…

command-and-controldata-exfiltrationpayload-generation+2
581 year ago
octohook preview

octohook

GitHubdsnezhkov/octohook

Git Web Hook Tunnel for C2

command-and-controlpayload-developmentpenetration-testing+2
289 years ago
CVE-2026-34227 preview

CVE-2026-34227

GitHubskoveit/cve-2026-34227

Proof-of-concept demonstrating CORS to CSRF chain on Sliver's unauthenticated MCP interface, enabling silent interaction with C2 from any webpage.

command-and-controlexploitationred-teaming+2
16 months ago
DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint- preview

DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-

GitHubsastraadiwiguna-purpleeliteteaming/ddos-purple-teaming-offensive-multi-vector-7-tier-defensive-holistic-blueprint-

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

cloud-securitycommand-and-controldefensive-tools+9
8 months ago
HRShell preview
Archived

HRShell

GitHubchrispetrou/hrshell

HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.

command-and-controlencryption-decryption-toolsexploitation+7
2485 years ago
CVE-2024-23700-C2-Server preview

CVE-2024-23700-C2-Server

GitHubkaitokidc500/cve-2024-23700-c2-server

Source code minh họa máy chủ c2 demo kịch bản thực thi của CVE-2024-23700

android-securitycommand-and-controldata-exfiltration+9
1 month ago
Invoke-SelfSignedWebRequest preview

Invoke-SelfSignedWebRequest

GitHub0sm0s1z/invoke-selfsignedwebrequest

This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and press on with…

command-and-controlids-ips-evasionpenetration-testing+4
129 years ago
pwnlift preview

pwnlift

GitHubrasta-mouse/pwnlift

Easy peasy file uploads

data-exfiltrationpenetration-testingremote-access-tool+2
443 months ago
meteor preview

meteor

GitHubdegenerat3/meteor

A cross-platform C2/teamserver supporting multiple transport protocols, written in Go.

command-and-controlexploit-frameworksnetwork-security+4
453 years ago
beef preview

beef

GitHubbeefproject/beef

The Browser Exploitation Framework Project

command-and-controlexploitationexploit-frameworks+8
11.0k2 days ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.8k18h 8m ago
Previous12…9Next