Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
105 results
createdump preview

createdump

GitHubrweijnen/createdump

Leverage WindowsApp createdump tool to obtain an lsass dump

impersonation-toolspassword-attackspost-exploitation+1
149
1 year ago
PiX-C2 preview

PiX-C2

GitHubrobertdavis1/pix-c2

Ping Exfiltration Command and Control (PiX-C2)

command-and-controlnetwork-securitypacket-sniffing-analysis+3
3111 years ago
Elite preview

Elite

GitHubcobbr/elite

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

command-and-controldynamic-code-analysisencryption-decryption-tools+6
1217 years ago
IronSharpPack preview

IronSharpPack

GitHubbc-security/ironsharppack

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

ids-ips-evasionpayload-developmentpayload-generation+2
1212 years ago
gdog preview

gdog

GitHubmaldevel/gdog

A fully featured Windows backdoor that uses Gmail as a C&C server

command-and-controlpayload-generationpost-exploitation+2
5079 years ago
gcat preview
Archived

gcat

GitHubbyt3bl33d3r/gcat

A PoC backdoor that uses Gmail as a C&C server

command-and-controlexploitationpayload-development+4
1.4k7 years ago
SharpImpersonation preview

SharpImpersonation

GitHubs3cur3th1ssh1t/sharpimpersonation

A User Impersonation tool - via Token or Shellcode injection

impersonation-toolspost-exploitationprivilege-escalation+1
4214 years ago
redamon preview

redamon

GitHubsamugit83/redamon

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

ai-securityexploit-frameworkslateral-movement+8
2.3k19h 57m ago
twittor preview

twittor

GitHubpaulsec/twittor

A fully featured backdoor that uses Twitter as a C&C server

command-and-controlexploitationpayload-development+4
80910 years ago
SharpStay preview

SharpStay

GitHub0xthirteen/sharpstay

.NET tool for installing Windows persistence via registry keys, scheduled tasks, services, WMI events, COM hijacks, and LNK backdoors, supporting…

penetration-testingpersistence-mechanismspost-exploitation+1
4982 years ago
GRAT2 preview

GRAT2

GitHubr3nhat/grat2

We developed GRAT2 Command & Control (C2) project for learning purpose.

command-and-controleducationpayload-development+3
4115 years ago
redsails preview

redsails

GitHubbeetlechunks/redsails

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

ids-ips-evasionpenetration-testingpersistence-mechanisms+2
3068 years ago
FindObjects-BOF preview

FindObjects-BOF

GitHuboutflanknl/findobjects-bof

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.

command-and-controlpenetration-testingpost-exploitation+1
2733 years ago
CVE-2017-0213 preview

CVE-2017-0213

GitHubjbooz1/cve-2017-0213

A version of CVE-2017-0213 that I plan to use with an Empire stager

command-and-controlexploitationpayload-generation+3
18 years ago
SharpMove preview

SharpMove

GitHub0xthirteen/sharpmove

.NET Project for performing Authenticated Remote Execution

lateral-movementpenetration-testingpost-exploitation+2
4103 years ago
Ares preview

Ares

GitHubcerbersec/ares

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

binary-analysisdefensive-toolsencryption-decryption-tools+7
3374 years ago
DCOMUploadExec preview

DCOMUploadExec

GitHubdeepinstinct/dcomuploadexec

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

exploitationlateral-movementpayload-development+3
3941 year ago
NamedPipePTH preview

NamedPipePTH

GitHubs3cur3th1ssh1t/namedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+4
1465 years ago
Previous123456Next