Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
518 results
AtlasLdr preview

AtlasLdr

GitHubkrypteria/atlasldr

Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls

ids-ips-evasionpayload-developmentpenetration-testing+2
394
1 year ago
trojanizer preview

trojanizer

GitHubr00t-3xp10it/trojanizer

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros

command-and-controlexploitationids-ips-evasion+6
2958 years ago
Amsi_Bypass_In_2023 preview

Amsi_Bypass_In_2023

GitHubsenzee1984/amsi_bypass_in_2023

Amsi Bypass payload that works on Windwos 11

adversarial-attackexploitationids-ips-evasion+4
3803 years ago
AsmLdr preview

AsmLdr

GitHub0xninjacyclone/asmldr

Dynamic shellcode loader with sophisticated evasion capabilities

ids-ips-evasionpayload-developmentpayload-generation+3
34610 months ago
Burp2Malleable preview

Burp2Malleable

GitHubcodextf2/burp2malleable

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

command-and-controlids-ips-evasionpayload-development+2
4183 years ago
SleepyCrypt preview

SleepyCrypt

GitHubsolomonsklash/sleepycrypt

A shellcode function to encrypt a running process image when sleeping.

ids-ips-evasionpayload-developmentred-teaming+1
3384 years ago
Christmas preview

Christmas

GitHubmaldev-academy/christmas

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

adversarial-attackids-ips-evasionpayload-development+3
2592 years ago
Bitmancer preview

Bitmancer

GitHubzimawhit3/bitmancer

Nim Library for Offensive Security Development

binary-analysisids-ips-evasionpayload-development+4
2002 years ago
SharpKiller preview

SharpKiller

GitHubs1lkys/sharpkiller

Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8

exploitationids-ips-evasionpayload-development+3
3511 year ago
ntdlll-unhooking-collection preview

ntdlll-unhooking-collection

GitHubsaadahla/ntdlll-unhooking-collection

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

ids-ips-evasionpayload-developmentpenetration-testing+2
2033 years ago
ExecIT preview

ExecIT

GitHubflorylsk/execit

Execute shellcode files with rundll32

ids-ips-evasionmalware-analysispayload-development+4
2242 years ago
fileless-xec preview

fileless-xec

GitHubariary/fileless-xec

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

command-and-controlexploitationids-ips-evasion+7
2102 years ago
D1rkSleep preview

D1rkSleep

GitHubsaadahla/d1rksleep

Improved version of EKKO by @5pider that Encrypts only Image Sections

adversarial-attackids-ips-evasionpayload-development+2
1243 years ago
freeBokuLoader preview

freeBokuLoader

GitHubs4ntiagop/freebokuloader

A simple BOF that frees UDRLs

ids-ips-evasionpayload-developmentpost-exploitation+1
1244 years ago
SharpWhispers preview

SharpWhispers

GitHubsecforce/sharpwhispers

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

ids-ips-evasionpayload-developmentpost-exploitation+2
1123 years ago
LibTP preview

LibTP

GitHubrasta-mouse/libtp

Crystal Palace library for proxying Nt API calls via the Threadpool

adversarial-attackids-ips-evasionpayload-development+2
10710 months ago
zoshrinkC2 preview

zoshrinkC2

GitHubdemon-i386/zoshrinkc2

DNS over HTTPS targeted malware (only runs once)

command-and-controlcryptographyids-ips-evasion+3
973 years ago
twoface preview

twoface

GitHubsynacktiv/twoface

"Two-Face" Rust binary on Linux

ids-ips-evasionpayload-developmentpenetration-testing+1
529 months ago
Previous1…567…29Next