Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
353 results
Anti-Virus-Evading-Payloads preview

Anti-Virus-Evading-Payloads

GitHubrosesecurity/anti-virus-evading-payloads

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

adversarial-attackeducationexploitation+4
749
1 month ago
CallstackSpoofingPOC preview

CallstackSpoofingPOC

GitHubpard0p/callstackspoofingpoc

C++ self-Injecting dropper based on various EDR evasion techniques.

adversarial-attackids-ips-evasionpayload-development+1
4442 years ago
DotNET_XorCryptor preview

DotNET_XorCryptor

GitHubdosx-dev/dotnet_xorcryptor

A new simple and powerfull packer for malware

adversarial-attackcryptographypayload-development+1
1072 years ago
DutchOven preview

DutchOven

GitHubloosehose/dutchoven

Application-scoped Windows network brownouts in native C and BOF form

adversarial-attackchaos-engineeringnetwork-security+2
231 month ago
promptfoo preview

promptfoo

GitHubpromptfoo/promptfoo

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and…

adversarial-attackai-securitydevsecops+5
25.7k12h 35m ago
DiagTrackEoP preview

DiagTrackEoP

GitHubwh04m1001/diagtrackeop

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

adversarial-attackexploitationpenetration-testing+3
884 years ago
HyperDeceit preview

HyperDeceit

GitHubxyrem/hyperdeceit

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

adversarial-attackbinary-analysisids-ips-evasion+3
3833 years ago
AI-Vulnerabilities-Playground preview

AI-Vulnerabilities-Playground

GitHubowasp/ai-vulnerabilities-playground

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

adversarial-attackai-securityctf+4
235 months ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

adversarial-attackai-securitycurated-resources+6
1.5k1 day ago
CVE-2026-23010-CCSDS-Telecommand-Replay-Without-Sequence-Number preview

CVE-2026-23010-CCSDS-Telecommand-Replay-Without-Sequence-Number

GitHubgeorge0papasotiriou/cve-2026-23010-ccsds-telecommand-replay-without-sequence-number

PoC simulation of a critical CCSDS telecommand replay vulnerability in satellite command systems, demonstrating missing sequence-number validation…

adversarial-attackexploitationvulnerability-analysis
2 months ago
ShimMe preview

ShimMe

GitHubdeepinstinct/shimme

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

adversarial-attackexploitationpost-exploitation+2
1461 year ago
Disable-TamperProtection preview

Disable-TamperProtection

GitHubalteredsecurity/disable-tamperprotection

A POC to disable TamperProtection and other Defender / MDE components

adversarial-attackpenetration-testingpost-exploitation+1
2582 years ago
CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation preview

CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation

GitHubgeorge0papasotiriou/cve-2026-21019-kubernetes-cronjob-suspended-execution-via-time-manipulation

Reproduces CVE-2026-21019 by manipulating node clock to force early Kubernetes CronJob execution; includes vulnerable YAML manifest and Python…

adversarial-attackcloud-infrastructure-securitycloud-security+3
2 months ago
delirium-ai-safety-benchmark preview

delirium-ai-safety-benchmark

GitLabtoxy4ny/delirium-ai-safety-benchmark

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…

adversarial-attackai-securityeducation+2
12 months ago
CrystalPotato preview

CrystalPotato

GitHubricardojoserf/crystalpotato

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

adversarial-attackexploitationpenetration-testing+3
1261 month ago
PSBits preview

PSBits

GitHubgtworek/psbits

Simple (relatively) things allowing you to dig a bit deeper than usual.

adversarial-attackexploitationpenetration-testing+5
3.5k1 month ago
APTSimulator preview

APTSimulator

GitHubnextronsystems/aptsimulator

A toolset to make a system look as if it was the victim of an APT attack

adversarial-attackdefensive-toolseducation+3
2.8k1 year ago
EDRSilencer preview

EDRSilencer

GitHubnetero1010/edrsilencer

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

adversarial-attackids-ips-evasionpost-exploitation+1
1.9k1 year ago
Previous12…20Next