Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
backdoorme preview

backdoorme

GitHubkkevsterrr/backdoorme

SSH-based post-exploitation framework deploying persistent backdoors (bash, Python, Metasploit) with modules for cron, startup, and privilege…

command-and-controlpayload-generationpenetration-testing+5
747
8 years ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

adversarial-attackcommand-and-controleducation+9
1.1k21 days ago
DLHell preview

DLHell

GitHubsynacktiv/dlhell

Windows DLL proxying tool for local and remote DLL hijacking via SMB and DCOM. Generates proxy DLL payloads with custom commands, supporting Kerberos…

exploitationlateral-movementpayload-development+3
1712 years ago
IIS-Backdoor preview

IIS-Backdoor

GitHubnu11secur1ty/iis-backdoor

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

command-and-controlexploitationids-ips-evasion+4
346 years ago
blackpill preview
Archived

blackpill

GitHubshard77/blackpill

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

binary-exploitationcommand-and-controlids-ips-evasion+7
3385 months ago
IIS-Raid preview

IIS-Raid

GitHub0x09al/iis-raid

A native backdoor module for Microsoft IIS (Internet Information Services)

command-and-controlpassword-crackingpersistence-mechanisms+1
5536 years ago
PwnLnX preview

PwnLnX

GitHubthatstraw/pwnlnx

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

command-and-controlpayload-generationpenetration-testing+3
2264 years ago
DLLPasswordFilterImplant preview

DLLPasswordFilterImplant

GitHubgosecure/dllpasswordfilterimplant

DLL Password Filter Implant with Exfiltration Capabilities

data-exfiltrationpenetration-testingpersistence-mechanisms+2
1366 years ago
Ares preview

Ares

GitHubsweetsoftware/ares

Python-based RAT with a web-based C2 server and cross-platform agent builder. Supports remote shell execution, file transfer, screenshot capture,…

command-and-controlpayload-generationpersistence-mechanisms+2
1.6k8 years ago
Sandman preview

Sandman

GitHubidov31/sandman

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

command-and-controlpayload-generationpersistence-mechanisms+2
8172 years ago
SmmBackdoor preview

SmmBackdoor

GitHubcr4sh/smmbackdoor

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

exploitationfirmware-analysishardware-hacking+4
6332 years ago
ForgeCert preview

ForgeCert

GitHubghostpack/forgecert

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

authenticationexploitationpayload-generation+1
7153 years ago
ChromeAlone preview

ChromeAlone

GitHubpraetorian-inc/chromealone

A tool to transform Chromium browsers into a C2 Implant

command-and-controlpayload-developmentpersistence-mechanisms+6
60110 months ago
Lilith preview

Lilith

GitHubwerkamsus/lilith

Lightweight C++ RAT for Windows with remote command execution via CMD/Powershell, keylogging, script execution, auto-install persistence, and…

command-and-controlpayload-generationpenetration-testing+4
7506 years ago
LdrLockLiberator preview

LdrLockLiberator

GitHubelliotkillick/ldrlockliberator

Offensive Windows technique collection for escaping or bypassing Loader Lock to run arbitrary code from DllMain, enabling reliable DLL hijacking and…

exploitationpayload-developmentpersistence-mechanisms+2
4351 year ago
DllShimmer preview

DllShimmer

GitHubprint3m/dllshimmer

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

adversarial-attackpayload-developmentpenetration-testing+2
7520 years ago
acCOMplice preview

acCOMplice

GitHubnccgroup/accomplice

Tools for discovery and abuse of COM hijacks

payload-developmentpersistence-mechanismspost-exploitation+1
3396 years ago
Mystikal preview

Mystikal

GitHubd00mfist/mystikal

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

adversarial-attackcommand-and-controlpayload-development+4
3262 years ago
Previous1234Next