Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
265 results
anamnesis-release preview

anamnesis-release

GitHubseanheelan/anamnesis-release

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

ai-securitybinary-exploitationeducation+9
632
6 months ago
NXLoader preview

NXLoader

GitHubdavidbuchanan314/nxloader

My first Android app: Launch Fusée Gelée payloads from stock Android (CVE-2018-6242)

android-securityexploitationhardware-iot-security+2
5643 years ago
D1rkLdr preview

D1rkLdr

GitHubsaadahla/d1rkldr

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

ids-ips-evasionpayload-developmentred-teaming+1
3233 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5423 years ago
Burp2Malleable preview

Burp2Malleable

GitHubcodextf2/burp2malleable

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

command-and-controlids-ips-evasionpayload-development+2
4183 years ago
xsser preview

xsser

GitHubvarbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

exploitationpayload-developmentpenetration-testing+3
4236 years ago
Nim-RunPE preview

Nim-RunPE

GitHubs3cur3th1ssh1t/nim-runpe

A Nim implementation of reflective PE-Loading from memory

binary-exploitationexploitationmalware-analysis+3
2961 year ago
ropium preview

ropium

GitHubboyan-milanov/ropium

Automated ROP chain builder that extracts and analyzes gadgets from binaries using semantic queries, supporting X86/X64 architectures with a Python…

binary-exploitationexploit-frameworkspayload-development+2
4024 years ago
cve-2017-7494 preview

cve-2017-7494

GitHubbetab0t/cve-2017-7494

Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)

exploitationpayload-developmentpenetration-testing+2
1819 years ago
UnhookMe preview

UnhookMe

GitHubmgeeky/unhookme

Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

defensive-toolspayload-developmentred-teaming
3484 years ago
CoercedPotatoRDLL preview

CoercedPotatoRDLL

GitHubsokarepo/coercedpotatordll

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

exploitationpayload-developmentpenetration-testing+4
2272 years ago
ntdlll-unhooking-collection preview

ntdlll-unhooking-collection

GitHubsaadahla/ntdlll-unhooking-collection

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

ids-ips-evasionpayload-developmentpenetration-testing+2
2033 years ago
FruityC2 preview

FruityC2

GitHubxtr4nge/fruityc2

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

command-and-controlexploit-frameworkspayload-development+4
2068 years ago
Fiber preview

Fiber

GitHubkudaes/fiber

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

payload-developmentpost-exploitationred-teaming
2452 years ago
Project-Onyx preview

Project-Onyx

GitHubx-3306/project-onyx

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

ai-securitycommand-and-controlcryptography+6
1171 month ago
dropengine preview

dropengine

GitHubs0lst1c3/dropengine

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

defensive-toolsexploit-frameworkspayload-development+5
2135 years ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1622 years ago
JavaPayload preview

JavaPayload

GitHubschierlm/javapayload

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

exploitationmisconfigurationpayload-development+3
1271 year ago
Previous123…15Next