Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
12.0k7h 44m ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
68713 days ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k27 days ago
MMSkillRisk preview

MMSkillRisk

GitHubkaill-jlq/mmskillrisk

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

adversarial-attackai-securitydata-exfiltration+7
26 days ago
metta preview

metta

GitHububer-common/metta

An information security preparedness tool to do adversarial simulation.

adversarial-attackdefensive-toolseducation+8
1.1k8 years ago
xspawn preview

xspawn

GitHubcenobyte-vincit/xspawn

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

adversarial-attackids-ips-evasionpersistence-mechanisms+2
1 month ago
PSBits preview

PSBits

GitHubgtworek/psbits

Simple (relatively) things allowing you to dig a bit deeper than usual.

adversarial-attackexploitationpenetration-testing+5
3.5k1 month ago
Mystikal preview

Mystikal

GitHubd00mfist/mystikal

macOS Initial Access Payload Generator

adversarial-attackcommand-and-controlpayload-development+4
3272 years ago
PurpleSharp preview

PurpleSharp

GitHubmvelazc0/purplesharp

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

adversarial-attackeducationlateral-movement+4
8471 year ago
no-defender preview
Archived

no-defender

GitHubes3n1n/no-defender

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

adversarial-attackids-ips-evasionpenetration-testing+3
2.0k2 years ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

adversarial-attackcommand-and-controleducation+9
1.1k14 days ago
GadgetToJScript preview

GadgetToJScript

GitHubmed0x2e/gadgettojscript

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

adversarial-attackexploitationlateral-movement+5
1.1k5 years ago
CobaltWhispers preview

CobaltWhispers

GitHubnvisosecurity/cobaltwhispers

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

adversarial-attackcommand-and-controlids-ips-evasion+4
2433 years ago
badsuccessor preview

badsuccessor

GitHubcybrly/badsuccessor

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

adversarial-attackexploitationinformation-gathering+7
1221 year ago
PoC-Malware-TTPs preview

PoC-Malware-TTPs

GitHubknight0x07/poc-malware-ttps

PoC-Malware-TTPs

adversarial-attackcommand-and-controlpayload-development+4
483 years ago
DllShimmer preview

DllShimmer

GitHubprint3m/dllshimmer

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

adversarial-attackpayload-developmentpenetration-testing+2
7551 year ago
PSpersist preview

PSpersist

GitHubsaadahla/pspersist

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

adversarial-attackpenetration-testingpersistence-mechanisms+2
823 years ago
RustyWater-ShellCode-Dropper preview

RustyWater-ShellCode-Dropper

GitHubs3n4t0r-0x0/rustywater-shellcode-dropper

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

binary-exploitationcommand-and-controlexploitation+9
1062 months ago