Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
200 results
BloodBash preview

BloodBash

GitHubsquidsec/bloodbash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

cloud-securityconfiguration-auditingidentity-access-management+6
406
1 day ago
Lastenzug preview

Lastenzug

GitHubcodewhitesec/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

command-and-controlids-ips-evasionpayload-development+3
2343 years ago
RPC-Backdoor preview

RPC-Backdoor

GitHubeladshamir/rpc-backdoor

A basic emulation of an "RPC Backdoor"

command-and-controllateral-movementpost-exploitation+3
2413 years ago
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

payload-developmentpost-exploitationred-teaming+1
5132 years ago
CallStackSpoofer preview

CallStackSpoofer

GitHubwithsecurelabs/callstackspoofer

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

adversarial-attackids-ips-evasionpost-exploitation+1
5931 year ago
AutoHoneyPoC preview

AutoHoneyPoC

GitHubzephrfish/autohoneypoc

AutoPoC Generator HoneyPoC

defensive-toolsexploitationpayload-generation+3
3621 days ago
vba2clr preview

vba2clr

GitHubmed0x2e/vba2clr

Running .NET from VBA

adversarial-attackpayload-developmentpost-exploitation+2
1473 years ago
Kernelhub preview

Kernelhub

GitHubascotbe/kernelhub

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

curated-resourceseducationexploitation+4
3.2k3 years ago
WTSRM2 preview

WTSRM2

GitHubrad9800/wtsrm2
ids-ips-evasionpayload-developmentred-teaming
1643 years ago
gopher47 preview

gopher47

GitHuban00brektn/gopher47

A third-party Gopher Assassin for the Havoc Framework.

command-and-controlpenetration-testingport-scanning+4
442 years ago
MemFiles preview

MemFiles

GitHuboctoberfest7/memfiles

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

command-and-controldata-exfiltrationpost-exploitation+1
4772 years ago
Lastenzug preview

Lastenzug

GitHubps1337/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

ids-ips-evasionpayload-developmentpost-exploitation+3
264 years ago
HyperDeceit preview

HyperDeceit

GitHubxyrem/hyperdeceit

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

adversarial-attackbinary-analysisids-ips-evasion+3
3863 years ago
NimBlackout preview

NimBlackout

GitHubhelixo32/nimblackout

Kill AV/EDR leveraging BYOVD attack

adversarial-attackeducationexploitation+2
4063 years ago
DEFCON-31-Syscalls-Workshop preview

DEFCON-31-Syscalls-Workshop

GitHubvirtualalllocex/defcon-31-syscalls-workshop

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

educationlabs-practicepayload-development+2
7741 year ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1622 years ago
DocPlz preview

DocPlz

GitHubsaadahla/docplz

Documents Exfiltration project for fun and educational purposes

data-exfiltrationpost-exploitationred-teaming
1432 years ago
CallstackSpoofingPOC preview

CallstackSpoofingPOC

GitHubpard0p/callstackspoofingpoc

C++ self-Injecting dropper based on various EDR evasion techniques.

adversarial-attackids-ips-evasionpayload-development+1
4422 years ago
Previous12…12Next