Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
277 results
PyIris preview

PyIris

GitHubnot-sekiun/pyiris

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

command-and-controlexploitationpayload-generation+4
327
5 days ago
iscsicpl_bypassUAC preview

iscsicpl_bypassUAC

GitHubhackerhouse-opensource/iscsicpl_bypassuac

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

exploitationpayload-developmentpost-exploitation+2
8466 months ago
webshells preview

webshells

GitHubblackarch/webshells

Curated collection of webshell scripts for web server remote access and command execution, supporting multiple languages including PHP, ASP, and JSP.

payload-generationpenetration-testingpost-exploitation+3
1.0k3 years ago
gh0st preview

gh0st

GitHubsin5678/gh0st

a open source remote administrator tool

command-and-controlpayload-developmentpenetration-testing+3
56013 years ago
DDexec preview

DDexec

GitHubarget13/ddexec

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

binary-exploitationpayload-generationpenetration-testing+3
8951 year ago
SmmBackdoor preview

SmmBackdoor

GitHubcr4sh/smmbackdoor

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

exploitationfirmware-analysishardware-hacking+4
6332 years ago
PoolParty preview

PoolParty

GitHubsafebreach-labs/poolparty

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

exploitationpayload-developmentpost-exploitation+3
1.3k2 years ago
WPForce preview

WPForce

GitHubn00py/wpforce

WordPress attack suite with API-based brute-force login, automated shell upload, post-exploitation modules including hash dumping, keylogger, BeEF…

password-attackspayload-generationpenetration-testing+2
9785 years ago
InvisibilityCloak preview

InvisibilityCloak

GitHubh4wkst3r/invisibilitycloak

Proof-of-concept obfuscation toolkit for C# post-exploitation tools

payload-developmentpost-exploitationred-teaming
6384 years ago
ScreenshotBOF preview

ScreenshotBOF

GitHubcodextf2/screenshotbof

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

command-and-controlpayload-developmentpenetration-testing+2
50727 days ago
xc preview

xc

GitHubxct/xc

A small reverse shell for Linux & Windows

command-and-controlpayload-generationpenetration-testing+3
6484 years ago
ChromeAlone preview

ChromeAlone

GitHubpraetorian-inc/chromealone

A tool to transform Chromium browsers into a C2 Implant

command-and-controlpayload-developmentpersistence-mechanisms+6
60110 months ago
Lilith preview

Lilith

GitHubwerkamsus/lilith

Lightweight C++ RAT for Windows with remote command execution via CMD/Powershell, keylogging, script execution, auto-install persistence, and…

command-and-controlpayload-generationpenetration-testing+4
7506 years ago
oracleShell preview

oracleShell

GitHubjas502n/oracleshell

Java-based Oracle database exploitation tool for command execution, file management, and reverse shell via PL/SQL functions.

database-securityexploitationpayload-development+2
5855 years ago
COFFLoader preview

COFFLoader

GitHubtrustedsec/coffloader

Run Beacon Object Files (BOFs) outside Cobalt Strike by parsing 64-bit COFF object files, with Beacon-compatible argument generation and helper…

binary-analysispayload-developmentpenetration-testing+2
6491 year ago
Dirty-Vanity preview

Dirty-Vanity

GitHubdeepinstinct/dirty-vanity

Windows code injection PoC that abuses the fork API to execute ntdll-based shellcode in a forked process and bypass EDRs.

adversarial-attackexploitationpayload-development+4
6783 years ago
hershell preview

hershell

GitHubsysdream/hershell

Cross-platform TCP reverse shell with TLS encryption, certificate pinning, shellcode injection, and meterpreter staging for red team operations.

command-and-controlexploitationpayload-generation+5
5297 years ago
NimPlant preview

NimPlant

GitHubchvancooten/nimplant

A light-weight first-stage C2 implant written in Nim (and Rust).

command-and-controlpayload-generationpenetration-testing-frameworks+2
9511 year ago
Previous1…345…16Next