Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
Windows-SignedBinary preview

Windows-SignedBinary

GitHubmr-un1k0d3r/windows-signedbinary

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

adversarial-attackbinary-analysishash-analysis+4
260
7 years ago
No-Consolation preview

No-Consolation

GitHubfortra/no-consolation

A BOF that runs unmanaged PEs inline

ids-ips-evasionpayload-developmentpenetration-testing-frameworks+2
7021 year ago
unhook-bof preview

unhook-bof

GitHubrsmudge/unhook-bof

Remove API hooks from a Beacon process.

adversarial-attackids-ips-evasionpost-exploitation+1
2834 years ago
unhook-bof preview

unhook-bof

GitHubcobalt-strike/unhook-bof

Remove API hooks from a Beacon process.

ids-ips-evasionpayload-developmentpenetration-testing-frameworks+2
774 years ago
EmbedPayloadInPng preview

EmbedPayloadInPng

GitHubmaldev-academy/embedpayloadinpng

Embed a payload inside a PNG file

cryptographydata-exfiltrationids-ips-evasion+2
3721 year ago
twoface preview

twoface

GitHubsynacktiv/twoface

"Two-Face" Rust binary on Linux

ids-ips-evasionpayload-developmentpenetration-testing+1
519 months ago
CVE-2025-10041 preview

CVE-2025-10041

GitHubnxploited/cve-2025-10041

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

exploitationids-ips-evasionpayload-generation+3
310 months ago
cs2modrewrite preview

cs2modrewrite

GitHubthreatexpress/cs2modrewrite

Convert Cobalt Strike profiles to modrewrite scripts

command-and-controlids-ips-evasionnetwork-security+3
6073 years ago
wordpress-fix-cve-2018-6389 preview

wordpress-fix-cve-2018-6389

GitHubyolabingo/wordpress-fix-cve-2018-6389

Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file

ids-ips-evasionmisconfigurationvulnerability-analysis+1
18 years ago
OutlookNTLM_CVE-2023-23397 preview

OutlookNTLM_CVE-2023-23397

GitHubmuhammad-ali007/outlookntlm_cve-2023-23397

Exploit for CVE-2023-23397 Outlook NTLM hash leak via malicious calendar invitations. Includes PowerShell weaponization, Responder integration, and…

exploitationids-ips-evasionincident-response+4
223 years ago
ExtensionSpoofer preview

ExtensionSpoofer

GitHubhenriksb/extensionspoofer

Spoof file icons and extensions in Windows

ids-ips-evasionimpersonation-toolsmalware-analysis+3
18724 days ago
File-Tunnel preview

File-Tunnel

GitHubfiddyschmitt/file-tunnel

Tunnel TCP connections through a file

ids-ips-evasionlateral-movementnetwork-mapping+3
1.1k19 days ago
CVE-2020-1938 preview

CVE-2020-1938

GitHubh7hac9/cve-2020-1938

Suricata and Bro detection rules for CVE-2020-1938 (Ghostcat) Tomcat AJP file read vulnerability, enabling network-level monitoring and alerting.

exploitationids-ips-evasionintrusion-detection+3
26 years ago
Nodejs-Tracer preview

Nodejs-Tracer

GitHubcheckpointsw/nodejs-tracer

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

anti-botdynamic-analysis-sandboxingids-ips-evasion+3
828 months ago
EDR-GhostLocker preview

EDR-GhostLocker

GitHubzero2504/edr-ghostlocker

AppLocker-Based EDR Neutralization

defensive-toolsexploitationids-ips-evasion+5
3428 months ago
BOF_ExecuteAssembly preview

BOF_ExecuteAssembly

GitHubntdallas/bof_executeassembly

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

binary-exploitationcommand-and-controlids-ips-evasion+4
1978 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsentinelxofficial/cve-2025-55182

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

exploitationids-ips-evasionpayload-development+5
12 months ago
Super-UEFIinSecureBoot-Disk preview

Super-UEFIinSecureBoot-Disk

GitHubvaldikss/super-uefiinsecureboot-disk

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot

exploitationhardware-securityids-ips-evasion+2
8414 years ago
Previous12Next