Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
621 results
xspawn preview

xspawn

GitHubcenobyte-vincit/xspawn

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

persistence-mechanismsids-ips-evasionpost-exploitation+2
2 days ago
memdumper preview

memdumper

GitHubcenobyte-vincit/memdumper

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

memory-forensicsids-ips-evasioninformation-gathering+4
12 days ago
dyen preview

dyen

GitHubcenobyte-vincit/dyen

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

payload-generationids-ips-evasionpost-exploitation+4
2 days ago
ShieldBreak preview

ShieldBreak

GitHub1neptune/shieldbreak

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

vulnerability-analysisexploitationids-ips-evasion+1
12 days ago
CVE-2025-7771 preview

CVE-2025-7771

GitHubenessakircolak/cve-2025-7771

ThrottleStop.sys Arbitrary Physical Memory R/W

privilege-escalationvulnerability-analysisexploitation+3
210 days ago
PSSW100AVB preview

PSSW100AVB

GitHubtihanyin/pssw100avb

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

ids-ips-evasionpost-exploitationpenetration-testing+5
1.4k2 months ago
Dumpy preview

Dumpy

GitHubkudaes/dumpy

Reuse open handles to dynamically dump LSASS.

exploitationids-ips-evasiondata-exfiltration+3
2462 years ago
SleepyCrypt preview

SleepyCrypt

GitHubsolomonsklash/sleepycrypt

A shellcode function to encrypt a running process image when sleeping.

ids-ips-evasionshellcodered-teaming+1
3384 years ago
EDRs preview

EDRs

GitHubmr-un1k0d3r/edrs

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

ids-ips-evasionreverse-engineeringpost-exploitation+3
2.2k4 months ago
Empire preview

Empire

GitHubbc-security/empire

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

penetration-testing-frameworkspayload-generationids-ips-evasion+5
5.2k18 days ago
FalsePositives preview

FalsePositives

GitHubdidierstevens/falsepositives

Tools that trigger False Positive AV alerts

defensive-toolspayload-generationids-ips-evasion+3
591 year ago
BokuLoader preview

BokuLoader

GitHubxforcered/bokuloader

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

penetration-testing-frameworksids-ips-evasionpost-exploitation+4
3352 years ago
Lastenzug preview

Lastenzug

GitHubcodewhitesec/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

ids-ips-evasionshellcodepost-exploitation+3
2343 years ago
WTSRM preview

WTSRM

GitHubrad9800/wtsrm

WTSRM

ids-ips-evasioneducationred-teaming+2
2154 years ago
RunAsWinTcb preview

RunAsWinTcb

GitHubtastypepperoni/runaswintcb
privilege-escalationexploitationids-ips-evasion+2
1384 years ago
MalwareApiLibrary preview

MalwareApiLibrary

GitHubmalwareapilib/malwareapilibrary

collection of apis used in malware development

ids-ips-evasionred-teamingpayload-development
2314 years ago
TamperingSyscalls preview

TamperingSyscalls

GitHubrad9800/tamperingsyscalls
ids-ips-evasionpost-exploitationred-teaming+1
5084 years ago
breakcyserver preview

breakcyserver

GitHubwaawaa/breakcyserver
privilege-escalationexploitationids-ips-evasion+2
523 years ago
Previous12…35Next