Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex preview

the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex

GitHubhunt-benito/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

adversarial-attackexploitationpayload-generation+3
11 days ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubhackspeak/cve-2026-64638

Proof-of-concept exploiting WordPress pre-auth XSS to RCE via DOM clobbering, REST API abuse, and malicious plugin upload for server-side execution.…

adversarial-attackexploitationpayload-generation+4
116 days ago
CVE-2025-32432-PoC preview

CVE-2025-32432-PoC

GitHubezramansor/cve-2025-32432-poc

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

adversarial-attackexploitationpayload-generation+3
17 days ago
printnightmare-detection-lab preview

printnightmare-detection-lab

GitHubjoertx07/printnightmare-detection-lab

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

adversarial-attackeducationexploitation+6
20 days ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

adversarial-attackcommand-and-controleducation+9
1.1k21 days ago
NachoVPN preview

NachoVPN

GitHubamberwolfcyber/nachovpn

A delicious, but malicious SSL-VPN server 🌮

adversarial-attackexploitationnetwork-security+5
2685 months ago
DllShimmer preview

DllShimmer

GitHubprint3m/dllshimmer

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

adversarial-attackpayload-developmentpenetration-testing+2
7520 years ago
defcon33_silence_kill_edr preview

defcon33_silence_kill_edr

GitHubarosenmund/defcon33_silence_kill_edr

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

adversarial-attackeducationlabs-practice+6
3471 year ago
BloodfangC2 preview

BloodfangC2

GitHubzarkones/bloodfangc2

Modern PIC implant for Windows (64 & 32 bit)

adversarial-attackcommand-and-controlpayload-development+4
1051 year ago
IconJector preview

IconJector

GitHubd419h/iconjector

Inject DLLs into the explorer process using icons

adversarial-attackexploitationpayload-development+3
4161 year ago
ThreadlessInject preview

ThreadlessInject

GitHubccob/threadlessinject

Threadless Process Injection using remote function hooking.

adversarial-attackpayload-developmentpayload-generation+4
8251 year ago
winsos-poc preview

winsos-poc

GitHubthiagopeixoto/winsos-poc

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

adversarial-attackexploitationpayload-development+2
1122 years ago
DotNET_XorCryptor preview

DotNET_XorCryptor

GitHubdosx-dev/dotnet_xorcryptor

Encrypts .NET executables with a polymorphic stub, junk-code flooding, and entry-point proxy to protect malware payloads from static detection.

adversarial-attackcryptographypayload-development+1
1072 years ago
blenny preview

blenny

GitHubfrank2/blenny

A payload delivery system which embeds payloads in an executable's icon file!

adversarial-attackpayload-developmentpayload-generation+2
742 years ago
Mystikal preview

Mystikal

GitHubd00mfist/mystikal

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

adversarial-attackcommand-and-controlpayload-development+4
3262 years ago
Jormungandr preview

Jormungandr

GitHubidov31/jormungandr

Windows kernel-mode COFF loader for executing x64 kernel COFF payloads, supports NTOSKRNL/SSDT imports and client-driven loading for red-team…

adversarial-attackpayload-developmentpost-exploitation+1
2432 years ago
HeapCrypt preview

HeapCrypt

GitHubsaadahla/heapcrypt

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

adversarial-attackpayload-developmentpost-exploitation+1
2443 years ago
PE-Obfuscator preview

PE-Obfuscator

GitHubsaadahla/pe-obfuscator

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…

adversarial-attackexploitationpayload-development+2
2113 years ago
Previous12Next