Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
596 results
voidsyscall preview

voidsyscall

GitHubvoidsecsoftwares/voidsyscall

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

command-and-controlencryption-decryption-toolsids-ips-evasion+9
18
1 day ago
evillimiter preview

evillimiter

GitHubdavidsonrafaelk/evillimiter

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

ids-ips-evasioninformation-gatheringnetwork-mapping+4
77 days ago
burpFakeIP preview

burpFakeIP

GitHubthekingofduck/burpfakeip

Burp Suite extension for spoofing IP addresses in HTTP requests, enabling testing of server-side IP restrictions and bypassing IP-based access…

ids-ips-evasionimpersonation-toolspenetration-testing+2
1.7k3 years ago
tfo-connect-bypass preview

tfo-connect-bypass

GitHub4n4s4zi/tfo-connect-bypass

Using TCP Fast Open to bypass syscall-based networking rules (CVE-2026-63828/CVE-2026-72243 PoC)

exploitationids-ips-evasionnetwork-security+3
4 days ago
Terminator_Killer preview

Terminator_Killer

GitHubhika-sec/terminator_killer

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

exploitationids-ips-evasionpenetration-testing+3
119 days ago
iodine preview

iodine

GitHubyarrick/iodine

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

command-and-controldata-exfiltrationids-ips-evasion+4
8.0k1 year ago
lldp preview

lldp

GitHubwhispergate/lldp

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

adversarial-attackcommand-and-controlids-ips-evasion+1
2123 days ago
CS_SleepMask preview

CS_SleepMask

GitHubjas502n/cs_sleepmask

CS_SleepMask

ids-ips-evasionpayload-developmentpenetration-testing-frameworks+2
45 years ago
bedaisy-bypass preview

bedaisy-bypass

GitHubgmh5225/bedaisy-bypass

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

adversarial-attackids-ips-evasionred-teaming
42 years ago
mora-hwbp preview

mora-hwbp

GitHubdovughs/mora-hwbp

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

adversarial-attackdebuggersdefensive-tools+3
1623 days ago
xspawn preview

xspawn

GitHubcenobyte-vincit/xspawn

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

adversarial-attackids-ips-evasionpersistence-mechanisms+2
25 days ago
memdumper preview

memdumper

GitHubcenobyte-vincit/memdumper

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

digital-forensicsids-ips-evasioninformation-gathering+4
125 days ago
dyen preview

dyen

GitHubcenobyte-vincit/dyen

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

binary-analysiscryptographyids-ips-evasion+4
25 days ago
ShieldBreak preview

ShieldBreak

GitHub1neptune/shieldbreak

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

exploitationids-ips-evasionred-teaming+1
125 days ago
CVE-2025-7771 preview

CVE-2025-7771

GitHubenessakircolak/cve-2025-7771

ThrottleStop.sys Arbitrary Physical Memory R/W

exploitationids-ips-evasionpenetration-testing+3
191 month ago
PSSW100AVB preview

PSSW100AVB

GitHubtihanyin/pssw100avb

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

ai-securitycommand-and-controlids-ips-evasion+5
1.4k3 months ago
SleepyCrypt preview

SleepyCrypt

GitHubsolomonsklash/sleepycrypt

A shellcode function to encrypt a running process image when sleeping.

ids-ips-evasionpayload-developmentred-teaming+1
3385 years ago
EDRs preview

EDRs

GitHubmr-un1k0d3r/edrs

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

binary-analysiscurated-resourcesids-ips-evasion+3
2.2k5 months ago
Previous12…34Next