Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
SliverMirage preview

SliverMirage

GitHubdaniomass/slivermirage

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

binary-analysiscommand-and-controlexploitation+4
40
14 days ago
CVE-2024-30088__Windows-TOCTOU-exploit preview

CVE-2024-30088__Windows-TOCTOU-exploit

GitHubth3g3ntl3m4n84/cve-2024-30088__windows-toctou-exploit

This is a modified version of the original CVE-2024-30088 exploit, adapted to work in non-interactive environments (WinRM).

exploitationpenetration-testingpost-exploitation+1
4 months ago
Dirty-Vanity preview

Dirty-Vanity

GitHubdeepinstinct/dirty-vanity

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

adversarial-attackexploitationpayload-development+4
6783 years ago
Split preview

Split

GitHubkudaes/split

Apply a divide and conquer approach to bypass EDRs

adversarial-attackids-ips-evasionpayload-development+3
2872 years ago
freeMetsrvLoader preview

freeMetsrvLoader

GitHubattl4s/freemetsrvloader

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

command-and-controlpayload-developmentpost-exploitation+1
353 years ago
PatchlessCLRLoader preview

PatchlessCLRLoader

GitHubvoldesec/patchlessclrloader

.NET assembly loader with patchless AMSI and ETW bypass

ids-ips-evasionpayload-developmentpost-exploitation+1
3883 years ago
LsassReflectDumping preview

LsassReflectDumping

GitHuboffensive-panda/lsassreflectdumping

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

memory-forensicspassword-attackspost-exploitation+1
2201 year ago
dcshadow preview

dcshadow

GitHubshutdownrepo/dcshadow

Python alternative to Mimikatz lsadump::dcshadow

defensive-toolspenetration-testingpersistence-mechanisms+2
1621 year ago
CVE-2026-58424 preview

CVE-2026-58424

GitHubbridgeralderson/cve-2026-58424

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

authentication-authorizationexploitationpayload-development+4
21 month ago
chuckle preview

chuckle

GitHubnccgroup/chuckle

An automated SMB relay exploitation script.

exploitationlateral-movementpenetration-testing+3
1529 years ago
asminject preview

asminject

GitHubbishopfox/asminject

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

container-escapepayload-developmentpenetration-testing+2
1483 years ago
php-reverse-shell preview

php-reverse-shell

GitHubivan-sincek/php-reverse-shell

PHP shells that work on Linux OS, macOS, and Windows OS.

educationexploitationpenetration-testing+4
5746 months ago
rpef preview

rpef

GitHubmncoppola/rpef

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

embedded-systems-securityexploitationfirmware-analysis+6
12412 years ago
XeytanWin32-RAT preview

XeytanWin32-RAT

GitHubmelardev/xeytanwin32-rat

WORK IN PROGRESS. RAT written in C++ using Win32 API

command-and-controldata-exfiltrationexploitation+8
206 years ago
XeytanWxCpp-RAT preview

XeytanWxCpp-RAT

GitHubmelardev/xeytanwxcpp-rat

Work in Progress. RAT written in C++ using wxWidgets

command-and-controlinformation-gatheringpayload-development+3
116 years ago
Loki.Rat preview

Loki.Rat

GitHubthegeekht/loki.rat

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

command-and-controldata-exfiltrationlateral-movement+6
763 years ago
CVE-2020-0668 preview

CVE-2020-0668

GitHubycdxsb/cve-2020-0668

Make CVE-2020-0668 exploit work for version < win10 v1903 and version >= win10 v1903

binary-exploitationexploitationpayload-generation+2
144 years ago
abyss-c2 preview

abyss-c2

GitHubflags-alt/abyss-c2

Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning,…

command-and-controleducationexploit-frameworks+7
23 months ago
Previous12Next