Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
backdoor-apk preview

backdoor-apk

GitHubdana-at-cp/backdoor-apk

backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have…

android-securityeducationexploit-frameworks+2
2.4k
8 years ago
SourcePoint preview

SourcePoint

GitHubtylous/sourcepoint

Polymorphic C2 profile generator for Cobalt Strike that automates creation of evasive beacon configurations with randomized options for HTTP, DNS,…

command-and-controlexploit-frameworkspayload-generation+1
1.2k7 days ago
MaliciousMacroGenerator preview

MaliciousMacroGenerator

GitHubmr-un1k0d3r/maliciousmacrogenerator

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

malware-analysispayload-generationphishing-tools
8287 years ago
DDexec preview

DDexec

GitHubarget13/ddexec

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

binary-exploitationpayload-generationpenetration-testing+3
8991 year ago
ThreadlessInject preview

ThreadlessInject

GitHubccob/threadlessinject

Threadless Process Injection using remote function hooking.

adversarial-attackpayload-developmentpayload-generation+4
8222 years ago
AMSI.fail preview

AMSI.fail

GitHubflangvik/amsi.fail

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

defensive-toolsexploitationids-ips-evasion+2
4687 months ago
Skrull preview

Skrull

GitHubaaaddress1/skrull

Generates anti-copy malware launchers using Process Ghosting to bypass AV/EDR signature scanning and prevent automatic sample submission. Supports…

anti-botexploitationmalware-analysis+2
4594 years ago
KeeFarceReborn preview

KeeFarceReborn

GitHubd3lb3/keefarcereborn

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

data-exfiltrationpassword-attackspayload-generation+3
2993 years ago
CVE-2013-2729 preview

CVE-2013-2729

GitHubfeliam/cve-2013-2729

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

binary-exploitationexploitationfuzzing+3
246 years ago
PichichiH0ll0wer preview

PichichiH0ll0wer

GitHubitaymigdal/pichichih0ll0wer

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

binary-exploitationexploitationpayload-generation+3
641 year ago
CVE-2022-42889-Text4Shell-POC preview

CVE-2022-42889-Text4Shell-POC

GitHubalealeluyah/cve-2022-42889-text4shell-poc

This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id:…

exploitationpayload-generationpenetration-testing+2
133 years ago
CVE-2024-0012_CVE-2024-9474_PoC preview

CVE-2024-0012_CVE-2024-9474_PoC

GitHubtalatumlabs/cve-2024-0012_cve-2024-9474_poc

This PoC is targeting vulnerabilities in Palo Alto PAN-OS, specifically CVE-2024-0012 and CVE-2024-9474. This script automates the exploitation…

educationexploitationpayload-generation+3
81 year ago
Unauthenticated-RCE-FUXA-CVE-2023-33831 preview

Unauthenticated-RCE-FUXA-CVE-2023-33831

GitHubrodolfomarianocy/unauthenticated-rce-fuxa-cve-2023-33831

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

exploitationpayload-generationpenetration-testing+4
131 year ago
CVE-2024-25600-Bricks-Builder-plugin-for-WordPress preview

CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

GitHubtornad0007/cve-2024-25600-bricks-builder-plugin-for-wordpress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for…

command-and-controlexploitationpayload-generation+3
82 years ago
CVE-2024-25641 preview

CVE-2024-25641

GitHub5ma1l/cve-2024-25641

This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26

exploitationpayload-generationpenetration-testing+2
82 years ago
WPS-CVE-2022-24934 preview

WPS-CVE-2022-24934

GitHubmagicpipersec/wps-cve-2022-24934

PoC exploit server for CVE-2022-24934 that delivers a malicious payload via a fake WPS Update Server, targeting the wpsupdate.exe process for…

exploitationpayload-generationpenetration-testing+3
54 years ago
CVE-2022-45701 preview

CVE-2022-45701

GitHubgeniuszly/cve-2022-45701

it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script…

educationexploitationiot-security+6
52 years ago
BlueDucky preview

BlueDucky

GitHubsergeb250/blueducky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The…

bluetooth-securityexploitationpayload-generation+3
21 year ago
Previous123Next