Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
306 results
DccwBypassUAC preview

DccwBypassUAC

GitHubl3cr0f/dccwbypassuac

Windows 8.1 and 10 UAC bypass abusing WinSxS in "dccw.exe".

exploitationpayload-developmentpost-exploitation+1
3976 years ago
Remote preview

Remote

GitHubzibility/remote

参考Gh0st源码,实现的一款PC远程协助软件,拥有远程Shell、文件管理、桌面管理、消息发送等功能。

command-and-controlpayload-developmentpenetration-testing+3
23010 years ago
Brute-Ratel-C4-Community-Kit preview

Brute-Ratel-C4-Community-Kit

GitHubparanoidninja/brute-ratel-c4-community-kit

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

command-and-controlexploitationpayload-development+3
3032 years ago
GPU_ShellCode preview

GPU_ShellCode

GitHubh1d3r/gpu_shellcode

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

adversarial-attackpayload-developmentpost-exploitation+1
3194 years ago
SharpZipRunner preview

SharpZipRunner

GitHubjfmaes/sharpziprunner

Executes position independent shellcode from an encrypted zip

exploitationpayload-developmentpayload-generation+3
3035 years ago
PersistBOF preview

PersistBOF

GitHubn4kedturtle/persistbof

A BOF to automate common persistence tasks for red teamers

payload-generationpersistence-mechanismspost-exploitation+2
2973 years ago
GoSH preview

GoSH

GitHubredcode-labs/gosh

Golang reverse/bind shell generator

exploitationpayload-developmentpayload-generation+4
2274 years ago
DropSpawn_BOF preview

DropSpawn_BOF

GitHuboctoberfest7/dropspawn_bof

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

binary-exploitationexploitationpayload-development+4
2853 years ago
SharpProxyLogon preview

SharpProxyLogon

GitHubflangvik/sharpproxylogon

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

exploitationpayload-developmentpost-exploitation+3
2475 years ago
DNS-Persist preview

DNS-Persist

GitHub0x09al/dns-persist

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

command-and-controldns-analysispayload-generation+5
2078 years ago
Offensive-Rust preview

Offensive-Rust

GitHubwinsecurity/offensive-rust
exploitationpayload-developmentpenetration-testing+2
3022 years ago
PwnLnX preview

PwnLnX

GitHubthatstraw/pwnlnx

Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

command-and-controlpayload-generationpenetration-testing+3
2264 years ago
Girsh preview

Girsh

GitHubnodauf/girsh

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

command-and-controlexploitationpayload-generation+5
3593 years ago
HeapCrypt preview

HeapCrypt

GitHubsaadahla/heapcrypt

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

adversarial-attackpayload-developmentpost-exploitation+1
2453 years ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2967 months ago
SharpEventPersist preview

SharpEventPersist

GitHubimprosec/sharpeventpersist

Persistence by writing/reading shellcode from Event Log

payload-generationpersistence-mechanismspost-exploitation+1
3754 years ago
linux_injector preview

linux_injector

GitHubnamazso/linux_injector

A simple ptrace-less shared library injector for x64 Linux

adversarial-attackpayload-developmentpenetration-testing+3
2963 years ago
backdoors preview

backdoors

GitHubhackerhouse-opensource/backdoors

Tools for maintaining access to systems and proof-of-concept demonstrations.

command-and-controlpayload-developmentpersistence-mechanisms+3
1837 months ago
Previous1…567…17Next