Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
415 results
Dirty-Vanity preview

Dirty-Vanity

GitHubdeepinstinct/dirty-vanity

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

adversarial-attackexploitationpayload-development+4
678
3 years ago
PR0CESS preview

PR0CESS

GitHubaaaddress1/pr0cess

some gadgets about windows process and ready to use :)

exploitationmalware-analysispayload-development+3
6172 years ago
collateral-damage preview

collateral-damage

GitHubexploits-forsale/collateral-damage

Kernel exploit for Xbox SystemOS using CVE-2024-30088

binary-exploitationexploitationhardware-iot-security+3
5281 year ago
DInvoke preview

DInvoke

GitHubthewover/dinvoke

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

adversarial-attackpayload-developmentpost-exploitation+1
7933 years ago
xsser preview

xsser

GitHubvarbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

exploitationpayload-developmentpenetration-testing+3
4236 years ago
CallbackHell preview

CallbackHell

GitHubly4k/callbackhell

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

binary-exploitationexploitationpayload-development+4
4844 years ago
ScreenshotBOF preview

ScreenshotBOF

GitHubcodextf2/screenshotbof

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

command-and-controlpayload-developmentpenetration-testing+2
5081 month ago
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

payload-developmentpost-exploitationred-teaming+1
5132 years ago
PELoader preview

PELoader

GitHubhagrid29/peloader

PE loader with various shellcode injection techniques

binary-analysisexploitationmalware-analysis+4
4573 years ago
spawn preview

spawn

GitHubboku7/spawn

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

command-and-controlexploitationpayload-development+5
4643 years ago
DNSStager preview

DNSStager

GitHubmhaskar/dnsstager

Hide your payload in DNS

command-and-controldns-analysisexploitation+3
6223 years ago
pwn2own2020 preview

pwn2own2020

GitHubsslab-gatech/pwn2own2020

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

binary-exploitationexploitationpayload-development+4
4145 years ago
CVE-2021-1732-Exploit preview

CVE-2021-1732-Exploit

GitHubkalendsi/cve-2021-1732-exploit

CVE-2021-1732 Exploit

binary-exploitationexploitationpayload-development+2
4275 years ago
SerialKillerBypassGadgetCollection preview

SerialKillerBypassGadgetCollection

GitHubpwntester/serialkillerbypassgadgetcollection

Collection of bypass gadgets to extend and wrap ysoserial payloads

exploitationpayload-developmentpayload-generation+1
3894 years ago
SNOWCRASH preview

SNOWCRASH

GitHubredcode-labs/snowcrash

Generates cross-platform polyglot payloads (Bash/PowerShell) for command execution, reverse shells, and binary execution, with configurable delay and…

exploitationpayload-developmentpayload-generation
2444 years ago
bt2 preview

bt2

GitHubblazeinfosec/bt2

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

command-and-controlpayload-developmentpenetration-testing+3
20610 years ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4384 years ago
delete-self-poc preview

delete-self-poc

GitHublloydlabs/delete-self-poc

A way to delete a locked file, or current running executable, on disk.

payload-developmentpost-exploitationred-teaming
61810 months ago
Previous1…345…24Next