Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
Sinister preview

Sinister

GitHubpushpenderindia/sinister

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

data-exfiltrationinformation-gatheringpassword-cracking+5
466
1 year ago
AdaptixC2 preview

AdaptixC2

GitHubadaptix-framework/adaptixc2

AdaptixC2 is a highly modular advanced redteam toolkit

command-and-controlencryption-decryption-toolsexploit-frameworks+9
3.6k6 months ago
D3m0n1z3dShell preview

D3m0n1z3dShell

GitHubmatheuzsecurity/d3m0n1z3dshell

Demonized Shell is an Advanced Tool for persistence in linux.

persistence-mechanismspost-exploitationprivilege-escalation+1
4561 year ago
GoAT preview

GoAT

GitHubpetercunha/goat

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

command-and-controlexploitationlateral-movement+7
2619 years ago
NimSyscallPacker preview

NimSyscallPacker

GitHubs3cur3th1ssh1t/nimsyscallpacker

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

binary-exploitationexploitationlateral-movement+7
2152 months ago
phantom-keylogger preview

phantom-keylogger

GitHubmattiaalessi/phantom-keylogger

Phantom Keylogger is an advanced, stealth-enabled keystroke and visual intelligence gathering system.

command-and-controldata-exfiltrationids-ips-evasion+6
779 months ago
Advanced-Loader-Reverse-Engineering preview

Advanced-Loader-Reverse-Engineering

GitHubkaandemir993/advanced-loader-reverse-engineering

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

binary-analysiscode-analysiseducation+8
122 months ago
PhantomEvasion preview

PhantomEvasion

GitHubesskumar/phantomevasion

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

exploit-frameworkspayload-generationpenetration-testing+5
176 years ago
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

command-and-controlexploitationmemory-forensics+6
129 days ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
8 months ago
CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit preview

CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit

GitHubsimoesctt/ctt-proxylogon-rce-v1.0---convergent-time-theory-enhanced-microsoft-exchange-exploit

An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving…

command-and-controldata-exfiltrationexploitation+9
7 months ago
DeepRoot preview

DeepRoot

GitHubgeorge-yanni/deeproot

CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation…

binary-exploitationcommand-and-controleducation+6
8 months ago
Dr0p1t-Framework preview
Archived

Dr0p1t-Framework

GitHubd4vinci/dr0p1t-framework

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

anti-botcommand-and-controlexploitation+9
1.5k7 years ago
paradoxiaRAT preview

paradoxiaRAT

GitHubquantumcore/paradoxiarat

ParadoxiaRat : Native Windows Remote access Tool.

command-and-controlpassword-crackingpenetration-testing+4
8283 years ago
PwnLnX preview

PwnLnX

GitHubthatstraw/pwnlnx

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

command-and-controlpayload-generationpenetration-testing+3
2264 years ago
project-rvbbit preview

project-rvbbit

GitHubbuter-chkalova/project-rvbbit

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

defensive-toolseducationmalware-analysis+3
3329 days ago
Vidar-Stealer-Reverse-Engineering preview

Vidar-Stealer-Reverse-Engineering

GitHubkaandemir993/vidar-stealer-reverse-engineering

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

binary-analysiseducationforensics+7
21 month ago
Fsociety-CVE-2024-0670-CheckMK-LPE preview

Fsociety-CVE-2024-0670-CheckMK-LPE

GitHubnikopmpm/fsociety-cve-2024-0670-checkmk-lpe

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

exploitationpenetration-testingpersistence-mechanisms+4
4 days ago