Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
Payload-Download-Cradles preview

Payload-Download-Cradles

GitHubvirtualalllocex/payload-download-cradles

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

curated-resourcesids-ips-evasionpayload-development+3
258
4 years ago
C2Bridge preview

C2Bridge

GitHubcobbr/c2bridge

C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.

command-and-controlexploit-frameworkspayload-development+3
716 years ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1176 years ago
Dirty-Vanity preview

Dirty-Vanity

GitHubdeepinstinct/dirty-vanity

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

adversarial-attackexploitationpayload-development+4
6783 years ago
CTT-NFS-Vortex-RCE preview

CTT-NFS-Vortex-RCE

GitHubsimoesctt/ctt-nfs-vortex-rce

New Physics Disclosure This repository contains a full weaponized exploit for **CVE-2026-21509**, targeting the Windows Network File System (NFSv4.1)…

binary-exploitationexploitationexploit-frameworks+1
37 months ago
macos_app_structure preview

macos_app_structure

GitHubyo-yo-yo-jbo/macos_app_structure

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

educationids-ips-evasionpayload-development+2
471 month ago
Beginners-Guide-to-Obfuscation preview

Beginners-Guide-to-Obfuscation

GitHubbc-security/beginners-guide-to-obfuscation

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

educationids-ips-evasionlabs-practice+3
1.1k2 years ago
UnCanny preview

UnCanny

GitHub0xhossam/uncanny

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

educationexploitationlateral-movement+4
882 months ago
invoker preview
Archived

invoker

GitHubivan-sincek/invoker

Penetration testing utility and antivirus assessment tool.

binary-analysiseducationexploitation+6
3123 years ago
Cronos preview

Cronos

GitHubidov31/cronos

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

cryptographyids-ips-evasionpayload-development+2
6282 years ago
FunctionStomping preview
Archived

FunctionStomping

GitHubidov31/functionstomping

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

binary-exploitationdefensive-toolsexploitation+7
7062 years ago
the-backdoor-factory preview

the-backdoor-factory

GitHubsecretsquirrel/the-backdoor-factory

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

binary-exploitationexploitationmalware-analysis+6
3.4k2 years ago
HWSyscalls preview

HWSyscalls

GitHubdec0ne/hwsyscalls

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

ids-ips-evasionpayload-developmentpenetration-testing+2
7353 years ago
CmdLineSpoofer preview

CmdLineSpoofer

GitHubplackyhacker/cmdlinespoofer

How to spoof the command line when spawning a new process from C#.

command-and-controleducationexploitation+5
1124 years ago
DotNET_XorCryptor preview

DotNET_XorCryptor

GitHubdosx-dev/dotnet_xorcryptor

A new simple and powerfull packer for malware

adversarial-attackcryptographypayload-development+1
1072 years ago
ShatteredFTP preview

ShatteredFTP

GitHubghostsec420/shatteredftp

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

exploitationpayload-developmentpenetration-testing+3
131 year ago
Grassmarlin-CVE-2026-6807-XXE-POC preview

Grassmarlin-CVE-2026-6807-XXE-POC

GitHubsectestannaquinn/grassmarlin-cve-2026-6807-xxe-poc

Reverse Engineered based on CISA disclosure of new CVE

data-exfiltrationexploitationpayload-development+3
24 months ago
malvinci preview

malvinci

GitHubgsoffmarket/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controldata-exfiltrationpayload-development+3
591 year ago
Previous12Next