Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
227 results
ParsingPeas preview

ParsingPeas

GitHubyuvalmil/parsingpeas

HTML parser for PEAS output with additional features

ctfeducationinformation-gathering+6
1621 month ago
Arcane preview

Arcane

GitHubtokyoneon/arcane

Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessary resources for APT repositories.

educationios-securitymobile-security+3
1576 years ago
Excalibur preview

Excalibur

GitHubdviros/excalibur

Excalibur is an Eternalblue exploit payload based "Powershell" for the Bashbunny project.

educationexploitationexploit-frameworks+9
1337 years ago
OptixGate preview

OptixGate

GitHubdarkcodersc/optixgate

Open-source multi-purpose remote access tool for Microsoft Windows

ctfeducationpost-exploitation+1
2075 months ago
airstrike preview

airstrike

GitHubsmokeme/airstrike

Customizable Stage0 C2 framework with C and Rust agent templates, a Flask backend, and a React dashboard for building and operating your own C2…

command-and-controleducationpayload-development+2
1742 years ago
moonwalk preview

moonwalk

GitHubteach2breach/moonwalk

find dll base addresses without PEB WALK

binary-analysiseducationpayload-development+2
1701 year ago
TTPRunner preview

TTPRunner

GitHubantonlovesdnb/ttprunner

Run TTPs, with AI!

command-and-controleducationexploit-frameworks+7
1406 months ago
ProcessStomping preview

ProcessStomping

GitHubnaksyn/processstomping

A variation of ProcessOverwriting to execute shellcode on an executable's section

binary-exploitationeducationpayload-development+3
1472 years ago
win32k-callback-detouring preview

win32k-callback-detouring

GitHubn0qword/win32k-callback-detouring

Abusing the win32k.sys kernel callback mechanism for arbitrary code execution

educationexploitationpayload-development+3
1194 months ago
ConTroll_Remote_Access_Trojan preview

ConTroll_Remote_Access_Trojan

GitHublithium876/controll_remote_access_trojan

Created a VERY SIMPLE remote access Trojan that will establish administrative control over any windows machine it compromises.

command-and-controleducationinformation-gathering+7
1038 years ago
rat-shell preview

rat-shell

GitHubstphivos/rat-shell

Windows Remote Access Trojan (RAT)

command-and-controleducationpayload-development+3
8910 years ago
Umbra preview

Umbra

GitHubh3xduck/umbra

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

command-and-controleducationencryption-decryption-tools+6
1364 years ago
BackDoorSim preview

BackDoorSim

GitHubhalildeniz/backdoorsim

Educational remote administration tool for learning RAT concepts, featuring file transfer, screenshot capture, system monitoring, and webcam access…

educationpenetration-testingpost-exploitation+2
1222 years ago
CmdLineSpoofer preview

CmdLineSpoofer

GitHubplackyhacker/cmdlinespoofer

How to spoof the command line when spawning a new process from C#.

command-and-controleducationexploitation+5
1124 years ago
DynastyPersist preview

DynastyPersist

GitHubtrevohack/dynastypersist

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

ctfpenetration-testingpersistence-mechanisms+3
16211 months ago
eden preview

eden

GitHubcobalt-strike/eden

A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (Draugr)

educationexploit-frameworkspayload-development+4
1388 months ago
RightHand-Persistence preview

RightHand-Persistence

GitHubi014n/righthand-persistence

COM Windows Persistence Technique

educationexploitationpersistence-mechanisms+2
904 months ago
Swift-Attack preview

Swift-Attack

GitHubcedowens/swift-attack

Unit tests for blue teams to aid with building detections for some common macOS post exploitation methods.

educationlabs-practicepost-exploitation+1
1073 years ago
Previous1…567…13Next