Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
306 results
zig-pe preview

zig-pe

GitHubthoxy67/zig-pe

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

binary-exploitationexploitationpayload-development+3
657 months ago
Orwell-RAT-and-Botnet preview

Orwell-RAT-and-Botnet

GitHubcorrecthorsebatterystaple-sudo/orwell-rat-and-botnet

Orwell is a RAT and Botnet designed as a trio of programs.

command-and-controlpayload-generationpost-exploitation+2
319 years ago
Powershell-C2 preview

Powershell-C2

GitHubenigma0x3/powershell-c2

PowerShell-based command and control framework using website-hosted payloads for persistent remote access and post-exploitation on Windows systems.

command-and-controlpayload-generationpenetration-testing+3
5012 years ago
KerberosRun preview

KerberosRun

GitHubdev-2null/kerberosrun

A little tool to play with Kerberos.

authenticationexploitationpassword-attacks+5
644 years ago
rustdllproxy preview

rustdllproxy

GitHubjohnswiftc/rustdllproxy

Generate Proxy DLLs in Rust

payload-developmentpayload-generationpenetration-testing+3
573 months ago
Bifrost preview

Bifrost

GitHubth3r4ven/bifrost

Bifrost C2. Open-source post-exploitation using Discord API

command-and-controlpayload-generationpost-exploitation+1
505 years ago
Monitor preview

Monitor

GitHubal1ex/monitor

A old way to Persistence

command-and-controlexploitationpayload-generation+4
526 years ago
Gh0st-light preview

Gh0st-light

GitHubholmesian/gh0st-light

精简之后的老东西

command-and-controlpayload-developmentpenetration-testing+3
3610 years ago
qu1ckdr0p2 preview

qu1ckdr0p2

GitHubbyinarie/qu1ckdr0p2

Quicky serve files over http or https using flask.

payload-developmentpayload-generationpenetration-testing+3
352 years ago
PoC-Malware-TTPs preview

PoC-Malware-TTPs

GitHubknight0x07/poc-malware-ttps

PoC-Malware-TTPs

adversarial-attackcommand-and-controlpayload-development+4
483 years ago
NoFaxGiven preview

NoFaxGiven

GitHubhackerhouse-opensource/nofaxgiven

Code Execution & Persistence in NETWORK SERVICE FAX Service

exploitationpayload-developmentpersistence-mechanisms+3
378 months ago
freeMetsrvLoader preview

freeMetsrvLoader

GitHubattl4s/freemetsrvloader

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

command-and-controlpayload-developmentpost-exploitation+1
343 years ago
MassDriver preview

MassDriver

GitHubsizeable-bingus/massdriver

Proxies sensitive API calls from shellcode to artifacts for CET-compatible clean call stacks, enabling stealthy payload execution and call stack…

binary-analysisexploitationpayload-development+2
334 months ago
Certi-Bhai preview

Certi-Bhai

GitHubincredibleindishell/certi-bhai

AD CS exploitation related stuff goes here

authenticationexploitationpayload-generation+4
406 months ago
nasm_linux_x86_64_pure_sharedlib preview

nasm_linux_x86_64_pure_sharedlib

GitHubtherealdreg/nasm_linux_x86_64_pure_sharedlib

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

exploitationpayload-developmentpost-exploitation+2
313 years ago
CVE-2020-1337 preview

CVE-2020-1337

GitHubneofito/cve-2020-1337

CVE-2020-1048 bypass: binary planting PoC

binary-exploitationexploitationpayload-development+4
326 years ago
PIRATE preview

PIRATE

GitHubgbrn1/pirate

Python Remote Access Tool

command-and-controlpayload-generationpenetration-testing+5
266 years ago
wp2shell preview

wp2shell

GitHubmcipekci/wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

command-and-controlexploitationpayload-development+7
152 months ago
Previous1…101112…17Next