Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
PPLcontrol preview

PPLcontrol

GitHubitm4n/pplcontrol

Windows tool to list, get, set, protect, and unprotect process protection levels (PP/L) for debugging, inspection, and privilege escalation.

defensive-toolsexploitationprivilege-escalation+1
405
3 years ago
NoArgs preview

NoArgs

GitHuboh-az/noargs

Windows API hooking tool that dynamically spoofs and conceals process arguments via Detours library and PEB manipulation, enabling stealthy process…

api-securitydefensive-toolsred-teaming
1522 years ago
BlockOpenHandle preview

BlockOpenHandle

GitHubsaadahla/blockopenhandle

Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory…

authentication-authorizationdefensive-toolsprivacy
1713 years ago
gibson preview

gibson

GitLabhackinglz/gibson

Network monitoring tool that maps process-to-network connections, identifies cloud providers, and detects beaconing activity

anomaly-detectioncloud-securitydefensive-tools+6
6 months ago
detection-validation preview

detection-validation

GitHubalwashali/detection-validation

Detection rule validation

adversarial-attackdefensive-toolsintrusion-detection+1
422 years ago
hotpatch-for-apache-log4j2 preview

hotpatch-for-apache-log4j2

GitHubcorretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

defensive-toolsexploitationincident-response+2
4973 years ago
herpaderping preview

herpaderping

GitHubjxy-s/herpaderping

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

defensive-toolsexploitationpenetration-testing
1.2k3 years ago
fake-sandbox preview

fake-sandbox

GitHubnuclearphoenixx/fake-sandbox

👁‍🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

anti-botdefensive-toolsids-ips-evasion+1
1411 year ago
WindowsJobLock preview

WindowsJobLock

GitHubnccgroup/windowsjoblock

Windows Process Lockdown Tool using Job Objects

defensive-toolsincident-responsesecurity-virtualization+1
7012 years ago
QLOG preview

QLOG

GitHubthreathunters-io/qlog

ETW-based Windows process creation logger that enriches events with file hashes, signatures, and parent process details, outputting to Windows…

defensive-toolsforensicsincident-response+1
444 years ago
DetectWindowsCopyOnWriteForAPI preview

DetectWindowsCopyOnWriteForAPI

GitHubnccgroup/detectwindowscopyonwriteforapi

Enumerate various traits from Windows processes as an aid to threat hunting

anomaly-detectiondefensive-toolsforensics+3
2004 years ago
KilledProcessCanary preview

KilledProcessCanary

GitHubnccgroup/killedprocesscanary

A canary designed to minimize the impact from certain Ransomware actors

anomaly-detectiondefensive-toolsdigital-forensics+2
1015 years ago
robusto preview

robusto

GitHubrotemreiss/robusto

Robust Subdomain Takeover Tool

cloud-securitydefensive-toolssubdomain-enumeration+1
34 years ago
SilentButDeadly preview

SilentButDeadly

GitHubloosehose/silentbutdeadly

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

command-and-controldefensive-toolsexploitation+7
45610 months ago
ghost preview

ghost

GitHubpandaadir05/ghost

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process…

binary-analysisdefensive-toolsforensics+6
3921 month ago
GoPurple preview

GoPurple

GitHubsh4hin/gopurple

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

defensive-toolseducationexploitation+6
4975 years ago
CVE-2021-3156-Mitigation-ShellScript-Build preview

CVE-2021-3156-Mitigation-ShellScript-Build

GitHubajtech-hue/cve-2021-3156-mitigation-shellscript-build

Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

authenticationdefensive-toolsincident-response+2
5 years ago
aegis preview

aegis

GitHubtobiaskocur/aegis

Kernel-mode process protection driver with user GUI

defensive-toolseducationexploitation+2
548 months ago
Previous1234Next