Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
120 results
dns-black-cat preview

dns-black-cat

GitHubzux0x3a/dns-black-cat

Multi platform toolkit for an interactive DNS shell commands exfiltration, by using DNS-Cat you will be able to execute system commands in shell mode…

command-and-controldata-exfiltrationdns-analysis+3
112
3 years ago
CVE-2025-62215 preview

CVE-2025-62215

GitHubtheman001/cve-2025-62215

Automated Windows kernel exploit suite targeting CVE-2025-62215 (race condition + double-free). Integrates WinDbg JS for dynamic offset extraction…

binary-exploitationdebuggerseducation+6
28 months ago
webhandler preview

webhandler

GitHublnxg33k/webhandler

Bash simulator to control a server using PHP system functions.

command-and-controlids-ips-evasionpayload-generation+3
1005 years ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
38.9k17h 30m ago
SysWhispers2 preview

SysWhispers2

GitHubjthuraisamy/syswhispers2

Generates header/ASM files for direct Windows system calls to bypass user-mode API hooks used by AV/EDR products, enabling stealthy red team…

binary-exploitationdefensive-toolsids-ips-evasion+5
1.8k3 years ago
SysWhispers3 preview

SysWhispers3

GitHubklezvirus/syswhispers3

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

defensive-toolsexploitationids-ips-evasion+5
1.7k2 years ago
Anti-Virus-Evading-Payloads preview

Anti-Virus-Evading-Payloads

GitHubrosesecurity/anti-virus-evading-payloads

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

adversarial-attackeducationexploitation+4
7501 month ago
PCShare preview

PCShare

GitHubxdnice/pcshare

HTTP-based remote access tool with DLL injection, process hollowing, and system hooking for persistent control, screen monitoring, file exfiltration,…

command-and-controldata-exfiltrationlateral-movement+9
5699 years ago
RootHelper preview

RootHelper

GitHubnullarray/roothelper

A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

exploitationinformation-gatheringpayload-generation+6
5055 years ago
RSPET preview

RSPET

GitHubpanagiks/rspet

Python-based reverse shell with TLS encryption, file transfer, UDP flooding/spoofing, plugin system, and RESTful API for post-exploitation and red…

command-and-controlexploitationpayload-generation+4
2638 years ago
grc2 preview

grc2

GitHubandreiverse/grc2

Lightweight C2 framework written in Nim for generating implants, managing listeners, and executing tasks via TCP/HTTP with a loot system for…

command-and-controlpayload-generationred-teaming+1
3453 years ago
CVE-2019-0708-EXP-Windows preview

CVE-2019-0708-EXP-Windows

GitHubcbwang505/cve-2019-0708-exp-windows

Single-file Windows exploit for CVE-2019-0708 (BlueKeep) that executes a reverse shell with SYSTEM privileges via RDP, statically compiled with…

exploitationpayload-generationpenetration-testing+3
3176 years ago
Nim-Reverse-Shell preview

Nim-Reverse-Shell

GitHubsn1r/nim-reverse-shell

A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell…

educationpayload-developmentpayload-generation+1
1243 years ago
CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit- preview

CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

GitHubsxyrxyy/cve-2025-8088-winrar-proof-of-concept-poc-exploit-

Proof-of-concept exploit for CVE-2025-8088 WinRAR path traversal vulnerability. Generates malicious RAR archives using alternate data streams to…

binary-exploitationeducationexploitation+3
731 year ago
blenny preview

blenny

GitHubfrank2/blenny

A payload delivery system which embeds payloads in an executable's icon file!

adversarial-attackpayload-developmentpayload-generation+2
742 years ago
phantom-keylogger preview

phantom-keylogger

GitHubmattiaalessi/phantom-keylogger

Stealth-enabled keystroke and visual intelligence gathering system for authorized red team operations. Features persistent surveillance, C2 tunnel,…

command-and-controldata-exfiltrationids-ips-evasion+6
778 months ago
Monitor preview

Monitor

GitHubal1ex/monitor

Windows persistence technique using AddMonitor to load a malicious DLL with SYSTEM privileges, enabling remote C2 via Meterpreter.

command-and-controlexploitationpayload-generation+4
535 years ago
CVE-2020-17530 preview

CVE-2020-17530

GitHubal1ex/cve-2020-17530

Proof-of-concept for Apache Struts2 S2-061 (CVE-2020-17530) demonstrating OGNL injection leading to remote code execution, with SSRF and system…

command-and-controleducationexploitation+3
295 years ago
Previous1234567Next