Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Payload Development

Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

NewestRelevanceMost popularRecently updated
3296 results
h-encore preview

h-encore

GitHubtheofficialflow/h-encore

Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

embedded-systems-securityprivilege-escalationexploitation+2
1.1k5 years ago
InvisibilityCloak preview

InvisibilityCloak

GitHubh4wkst3r/invisibilitycloak

Proof-of-concept obfuscation toolkit for C# post-exploitation tools

post-exploitationred-teamingpayload-development
6324 years ago
No-Consolation preview

No-Consolation

GitHubfortra/no-consolation

A BOF that runs unmanaged PEs inline

penetration-testing-frameworksids-ips-evasionpost-exploitation+2
7021 year ago
go-exploit preview

go-exploit

GitHubvulncheck-oss/go-exploit

Go-based exploit development framework with built-in phases for target verification, version scanning, exploitation, and C2. Supports multiple…

penetration-testing-frameworksvulnerability-scannersexploit-frameworks+3
4553 days ago
InjectProc preview

InjectProc

GitHubsecrary/injectproc

InjectProc - Process Injection Techniques [This project is not maintained anymore]

malware-analysiseducationpayload-development+1
9937 years ago
HWSyscalls preview

HWSyscalls

GitHubdec0ne/hwsyscalls

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

ids-ips-evasionpost-exploitationpenetration-testing+2
7353 years ago
CVE-2024-38063 preview

CVE-2024-38063

GitHubynwarcs/cve-2024-38063

poc for CVE-2024-38063 (RCE in tcpip.sys)

vulnerability-analysisexploitationfuzzing+3
6941 year ago
GadgetToJScript preview

GadgetToJScript

GitHubmed0x2e/gadgettojscript

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

payload-generationpersistence-mechanismsexploitation+5
1.1k5 years ago
DEFCON-31-Syscalls-Workshop preview

DEFCON-31-Syscalls-Workshop

GitHubvirtualalllocex/defcon-31-syscalls-workshop

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

shellcodeeducationred-teaming+2
7731 year ago
SysWhispers4 preview

SysWhispers4

GitHubjoasasantos/syswhispers4

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

ids-ips-evasionpost-exploitationred-teaming+2
5465 months ago
ExecuteAssembly preview

ExecuteAssembly

GitHubmed0x2e/executeassembly

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

privilege-escalationpersistence-mechanismsexploitation+8
5975 years ago
AceLdr preview

AceLdr

GitHubkyleavery/aceldr

Cobalt Strike UDRL for memory scanner evasion.

exploit-frameworksmemory-forensicspost-exploitation+2
1.0k2 years ago
Salsa-tools preview

Salsa-tools

GitHubhackplayers/salsa-tools

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

privilege-escalationencryption-decryption-toolsexploitation+7
5876 years ago
OffensiveCpp preview

OffensiveCpp

GitHublsecqt/offensivecpp

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

exploitationids-ips-evasionshellcode+6
7681 year ago
hershell preview

hershell

GitHublesnuages/hershell

Multiplatform reverse shell generator

encryption-decryption-toolspayload-generationexploitation+6
5926 years ago
nccfsas preview

nccfsas

GitHubnccgroup/nccfsas

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

penetration-testing-frameworksprivilege-escalationreconnaissance+8
6094 years ago
ScreenshotBOF preview

ScreenshotBOF

GitHubcodextf2/screenshotbof

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

post-exploitationpenetration-testingcommand-and-control+2
50324 days ago
OffensiveDLR preview

OffensiveDLR

GitHubbyt3bl33d3r/offensivedlr

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

privilege-escalationpersistence-mechanismscode-analysis+9
5264 years ago
Previous1…101112…100Next