Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
410 results
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k11h 15m ago
PEASS-ng preview

PEASS-ng

GitHubpeass-ng/peass-ng

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

educationexploitationexploit-frameworks+7
20.4k1 day ago
RedGhost preview

RedGhost

GitHubd4rk007/redghost

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

command-and-controllateral-movementpayload-generation+5
5425 years ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud-native C2 framework using cloud storage as dead-drop communication channel

cloud-securitycommand-and-controlencryption-decryption-tools+6
43 days ago
phpsploit preview

phpsploit

GitHubnil0x42/phpsploit

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

command-and-controlexploit-frameworkspayload-development+6
2.5k2 years ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicshash-analysis+8
11.0k11 months ago
Rubeus preview

Rubeus

GitHubghostpack/rubeus

Trying to tame the three-headed dog.

authenticationexploitationlateral-movement+6
5.1k9 months ago
malvinci preview

malvinci

GitHubgsoffmarket/malvinci

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

command-and-controldata-exfiltrationpayload-development+3
591 year ago
GodGenesis preview

GodGenesis

GitHubsaumyajeetdas/godgenesis

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

command-and-controldata-exfiltrationinformation-gathering+5
5312 years ago
TeamsImplant preview

TeamsImplant

GitHuballevon412/teamsimplant

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

command-and-controlexploit-frameworkspayload-development+5
2074 years ago
wmi-static-spoofer preview

wmi-static-spoofer

GitHubalex3434/wmi-static-spoofer

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

exploitationhardware-hackinghardware-iot-security+4
5147 years ago
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

cloud-securitycurated-resourceseducation+8
352 months ago
FakeMBR preview

FakeMBR

GitHubmalwaretech/fakembr

TDL4 style rootkit to spoof read/write requests to master boot record

binary-analysisexploitationmalware-analysis+2
13411 years ago
metta preview

metta

GitHububer-common/metta

An information security preparedness tool to do adversarial simulation.

adversarial-attackdefensive-toolseducation+8
1.1k8 years ago
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
411 days ago
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

cloud-securitycommand-and-controldata-exfiltration+5
11 days ago
RedbloodC2 preview

RedbloodC2

GitHubkira2040k/redbloodc2

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

command-and-controldata-exfiltrationencryption-decryption-tools+5
293 years ago
CVE-2020-1337 preview

CVE-2020-1337

GitHubneofito/cve-2020-1337

CVE-2020-1048 bypass: binary planting PoC

binary-exploitationexploitationpayload-development+4
326 years ago
Previous12…23Next