Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LitterBox — A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end. | Kitploit
Tools/GitHubGitHub/blacksnufkin/litterbox
Static AnalysisDynamic Analysis (Sandboxing)Malware AnalysisPenetration TestingRed TeamingPayload DevelopmentAI Security
GitHubblacksnufkin/litterbox

LitterBox

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

View Repository
1.5k1683 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

LitterBox

LitterBox Logo

Python Windows Linux Docker MCP Ask DeepWiki GitHub Stars

A self-hosted payload-analysis sandbox for red teams. Upload a sample, run static / dynamic / EDR analysis against it, get a Detection Score and a triggering-indicators breakdown — decide whether the payload is field-ready before it leaves the lab.

LitterBox can also dispatch payloads to a separate EDR-instrumented Windows VM (Elastic Defend or Fibratus) and pull the correlated detection alerts back into the results page.

While designed primarily for red teams, LitterBox is equally useful for blue teams running the same tools in their malware-analysis workflows.

Documentation

Operator and developer documentation lives in the LitterBox Wiki.

Installation

Windows

root@kitploit:~
git clone https://github.com/BlackSnufkin/LitterBox.git
cd LitterBox
python -m venv venv
.\venv\Scripts\Activate.ps1
pip install -r requirements.txt
python litterbox.py            # add --debug for verbose logging

Open http://127.0.0.1:1337. Requires Python 3.11+ and an admin shell.

Linux (Docker)

root@kitploit:~
git clone https://github.com/BlackSnufkin/LitterBox.git
cd LitterBox/Docker
chmod +x setup.sh
./setup.sh

The setup script provisions a Windows 10 container with KVM and runs LitterBox inside. Initial build takes ~1 hour.

  • Install monitor: http://localhost:8006
  • RDP: localhost:3389 (creds in the docker compose file)
  • LitterBox UI: http://127.0.0.1:1337 once setup completes

EDR setup (optional)

Drop one or more profile YAMLs under Config/edr_profiles/ and the upload page picks them up at boot. Full walkthroughs in the wiki: Whiskers Agent → Elastic Defend Setup or Fibratus Setup.

Scanners

Bundled binaries under Scanners/. Versions and last-update dates tracked here so operators can tell at a glance whether a scanner is current.

Version format: <release-version> or <release-version> (release) when the binary is pulled from an upstream release; <release-version> (\`)or just``` when built from source. Last-updated date is the upstream commit / release date, not the local build date.

When you refresh a scanner: replace the binary under its Scanners/<Name>/ directory and update the row above (version + date).

Contributing

See CONTRIBUTING.md. Work in feature branches on personal forks.

Support 🍺

Stars

Security Advisory

  • Development use only. This platform is designed for testing environments. Production deployment presents significant security risks.
  • Isolation required. Run only in isolated VMs or dedicated testing environments.
  • No warranty. Provided without guarantees; use at your own risk.
  • Legal compliance. Users are responsible for ensuring usage complies with applicable laws.

Acknowledgments

LitterBox stands on the work of these projects and their authors:

Interface

LitterBox Demo

Download Tool
TopicWiki page
How everything fits togetherApplication Architecture
Run static + every reachable EDR in parallelAll in One Pipeline
Dispatch payloads to a real EDR VMEDR Integration → Elastic Defend / Fibratus
Whiskers agent (install, endpoints, build)Whiskers Agent
Every HTTP endpointHTTP API Reference
CLI / Python lib / MCP for LLMsGrumpyCats CLI · GrumpyCats Library · LitterBoxMCP
What feeds the Detection ScoreDetection Score Explained
Configure scanners / paths / timeoutsConfiguration Reference
Add custom YARA rules / scannersYARA Rules Management · New Scanner
ScannerVersionLast updatedSource
PE-Sieve0.4.1.2 (f1dc39d)2026-05-02hasherezade/pe-sieve
Hollows-Hunter0.4.1.2 (e271f7e)2026-04-18hasherezade/hollows_hunter
Moneta5b653952024-03-16forrest-orr/moneta
Patriot—2024-12-29joe-desimone/patriot
Hunt-Sleeping-Beacons84dd3a92026-01-25thefLink/Hunt-Sleeping-Beacons
RedEdr3bd6b97 (EXE-only build)2026-05-03dobin/RedEdr
YARA (engine yara64.exe)—2024-12-29VirusTotal/yara
Elastic YARA rules (Scanners/Yara/rules/elastic-yara/)d131ea82026-04-30elastic/protections-artifacts
YARA-Forge Extended (Scanners/Yara/rules/YARAForge/)0.9.1 (release 20260503)2026-05-03YARAHQ/yara-forge
CheckPlz—2024-12-29BlackSnufkin/CheckPlz
Stringnalyzer—2025-01-27BlackSnufkin/Rusty-Playground
HolyGrail—2025-08-18BlackSnufkin/HolyGrail
ToolAuthor
YARA rules · Elastic DefendElastic Security
PE-Sieve · Hollows-Hunterhasherezade
MonetaForrest Orr
Patriotjoe-desimone
Hunt-Sleeping-BeaconsthefLink
RedEdrdobin
Fibratusrabbitstack
ThreatCheck (basis for CheckPlz)rasta-mouse
MalAPI reference DBmr.d0x