Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
BokuLoader preview

BokuLoader

GitHubxforcered/bokuloader

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

adversarial-attackcommand-and-controlids-ips-evasion+4
332
2 years ago
CallStackMasker preview

CallStackMasker

GitHubcobalt-strike/callstackmasker

A PoC implementation for dynamically masking call stacks with timers.

adversarial-attackpost-exploitationred-teaming
3153 years ago
AtomicTestHarnesses preview

AtomicTestHarnesses

GitHubredcanaryco/atomictestharnesses

Public Repo for Atomic Test Harness

adversarial-attackdefensive-toolspenetration-testing+1
2951 year ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2355 months ago
CobaltWhispers preview

CobaltWhispers

GitHubnvisosecurity/cobaltwhispers

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

adversarial-attackcommand-and-controlids-ips-evasion+4
2433 years ago
Percino preview

Percino

GitHubtunnelgre/percino

Evasive Golang Loader

adversarial-attackcommand-and-controlids-ips-evasion+4
1382 years ago
VehApiResolve preview

VehApiResolve

GitHubrad9800/vehapiresolve

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

adversarial-attackpayload-developmentred-teaming
1174 years ago
Purple-Team-Automation preview

Purple-Team-Automation

GitHubjoshuagodwin7929/purple-team-automation

Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.

adversarial-attackcommand-and-controlincident-response+6
5114 days ago
OneDriveUpdaterSideloading preview

OneDriveUpdaterSideloading

GitHubchoisg/onedriveupdatersideloading

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

adversarial-attackpayload-developmentred-teaming+1
1013 years ago
BloodfangC2 preview

BloodfangC2

GitHubzarkones/bloodfangc2

Modern PIC implant for Windows (64 & 32 bit)

adversarial-attackcommand-and-controlpayload-development+4
1031 year ago
EasyTokens preview

EasyTokens

GitHubsecdev02/easytokens

Kali365 - EvilTokens Replica

adversarial-attackauthenticationcloud-security+7
733 months ago
Red-Team-GOAD-Lab-Proxmox preview

Red-Team-GOAD-Lab-Proxmox

GitHubpho5nix/red-team-goad-lab-proxmox

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

adversarial-attackcommand-and-controldefensive-tools+7
4712 days ago
PSpersist preview

PSpersist

GitHubsaadahla/pspersist

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

adversarial-attackpenetration-testingpersistence-mechanisms+2
823 years ago
PoC-Malware-TTPs preview

PoC-Malware-TTPs

GitHubknight0x07/poc-malware-ttps

PoC-Malware-TTPs

adversarial-attackcommand-and-controlpayload-development+4
483 years ago
siphondns preview

siphondns

GitHubttpreport/siphondns

Covert data exfiltration via DNS

adversarial-attackcommand-and-controldata-exfiltration+3
531 year ago
detection-validation preview

detection-validation

GitHubalwashali/detection-validation

Detection rule validation

adversarial-attackdefensive-toolsintrusion-detection+1
422 years ago
GwisinMsi preview

GwisinMsi

GitHubchoisg/gwisinmsi

PoC MSI payload based on ASEC/AhnLab's blog post

adversarial-attackmalware-analysispayload-development+1
254 years ago
RedTeamSimmer preview

RedTeamSimmer

GitHubbreachsimrange/redteamsimmer

Web-based adversary emulation platform that orchestrates Atomic Red Team tests across Windows endpoints via Go agents, with MITRE ATT&CK mapping, APT…

adversarial-attackcommand-and-controldefensive-tools+7
111 month ago
Previous123Next