Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
injectAmsiBypass preview

injectAmsiBypass

GitHubboku7/injectamsibypass

Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.

exploit-frameworkspayload-developmentpenetration-testing+1
380
3 years ago
CVE-2026-49176_BOF preview

CVE-2026-49176_BOF

GitHub777erp/cve-2026-49176_bof

CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)

exploitationpayload-developmentpost-exploitation+2
51 month ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2986 months ago
amd-ryzen-master-driver-v17-exploit preview

amd-ryzen-master-driver-v17-exploit

GitHubtijme/amd-ryzen-master-driver-v17-exploit

Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).

binary-exploitationexploitationexploit-frameworks+4
1603 years ago
kernel-mii preview

kernel-mii

GitHubtijme/kernel-mii

Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.

exploit-frameworkspayload-developmentpenetration-testing+2
853 years ago
CobaltWhispers preview

CobaltWhispers

GitHubnvisosecurity/cobaltwhispers

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

adversarial-attackcommand-and-controlids-ips-evasion+4
2413 years ago
CVE-2024-26229-BOF preview

CVE-2024-26229-BOF

GitHubapkc/cve-2024-26229-bof

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

binary-exploitationexploitationexploit-frameworks+5
292 years ago
Elevate-System-Trusted-BOF preview

Elevate-System-Trusted-BOF

GitHubmr-un1k0d3r/elevate-system-trusted-bof

Cobalt Strike Beacon Object File that elevates an active beacon to SYSTEM and grants TrustedInstaller privileges through SetThreadToken token…

command-and-controlpayload-developmentpost-exploitation+2
1813 years ago
trustme preview

trustme

GitHubmeowmycks/trustme

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

command-and-controlexploitationimpersonation-tools+4
1365 months ago
CVE-2024-35250-BOF preview

CVE-2024-35250-BOF

GitHubro0tmylove/cve-2024-35250-bof

Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)

binary-exploitationexploitationexploit-frameworks+3
131 year ago
tgt-monitor-bof preview

tgt-monitor-bof

GitHubjakobfriedl/tgt-monitor-bof

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

authenticationlateral-movementpayload-development+3
1351 month ago
DNSRPC-BOF preview

DNSRPC-BOF

GitHubparadoxis/dnsrpc-bof

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

exploitationpayload-developmentpenetration-testing+2
501 month ago
CVE-2024-35250-BOF preview
Archived

CVE-2024-35250-BOF

GitHubyinsel/cve-2024-35250-bof

CVE-2024-35250 的 Beacon Object File (BOF) 实现。

exploitationpayload-developmentpenetration-testing+3
241 year ago