Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
290 results
Unwinder preview

Unwinder

GitHubkudaes/unwinder

Call stack spoofing for Rust

adversarial-attackids-ips-evasionpayload-development+2
3851 year ago
MagicSigner preview

MagicSigner

GitHubnamazso/magicsigner

Signtool for expired certificates

adversarial-attackauthentication-authorizationdefensive-tools+2
5253 years ago
NoFilter preview

NoFilter

GitHubdeepinstinct/nofilter

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

adversarial-attackexploitationpenetration-testing+3
3041 year ago
hwbp4mw preview

hwbp4mw

GitHubrad9800/hwbp4mw

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.

adversarial-attackdebuggersids-ips-evasion+2
2743 years ago
BrokenHill preview

BrokenHill

GitHubbishopfox/brokenhill

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

adversarial-attackai-securityexploitation+2
1741 year ago
CallStackMasker preview

CallStackMasker

GitHubcobalt-strike/callstackmasker

A PoC implementation for dynamically masking call stacks with timers.

adversarial-attackpost-exploitationred-teaming
3163 years ago
UAC-bypass preview

UAC-bypass

GitHubwinscripting/uac-bypass

PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…

adversarial-attackexploitationpenetration-testing+3
2439 years ago
AtomicTestHarnesses preview

AtomicTestHarnesses

GitHubredcanaryco/atomictestharnesses

Public Repo for Atomic Test Harness

adversarial-attackdefensive-toolspenetration-testing+1
2931 year ago
linux_injector preview

linux_injector

GitHubnamazso/linux_injector

A simple ptrace-less shared library injector for x64 Linux

adversarial-attackpayload-developmentpenetration-testing+3
2933 years ago
ShimMe preview

ShimMe

GitHubdeepinstinct/shimme

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

adversarial-attackexploitationpost-exploitation+2
1461 year ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2354 months ago
aad-bofs preview

aad-bofs

GitHubkozmer/aad-bofs

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

adversarial-attackcloud-infrastructure-securitycloud-security+5
1429 months ago
reverse-SynthID-text preview

reverse-SynthID-text

GitHubaloshdenny/reverse-synthid-text

reverse engineering SynthID for text

adversarial-attackai-securitycryptography+5
1098 months ago
ntqueueapcthreadex-ntdll-gadget-injection preview

ntqueueapcthreadex-ntdll-gadget-injection

GitHublloydlabs/ntqueueapcthreadex-ntdll-gadget-injection

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

adversarial-attackids-ips-evasionpayload-development+3
2673 years ago
CobaltWhispers preview

CobaltWhispers

GitHubnvisosecurity/cobaltwhispers

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

adversarial-attackcommand-and-controlids-ips-evasion+4
2413 years ago
modelaudit preview

modelaudit

GitHubpromptfoo/modelaudit

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

adversarial-attackai-securitydata-exfiltration+8
691 day ago
ezEmu preview

ezEmu

GitHubjwillyamz/ezemu

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)

adversarial-attackdefensive-toolseducation+3
1093 years ago
LibTP preview

LibTP

GitHubrasta-mouse/libtp

Crystal Palace library for proxying Nt API calls via the Threadpool

adversarial-attackids-ips-evasionpayload-development+2
10710 months ago
Previous1234…17Next