Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
157 results
AMSI.fail preview

AMSI.fail

GitHubflangvik/amsi.fail

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

defensive-toolsexploitationids-ips-evasion+2
463
6 months ago
SharpWebServer preview

SharpWebServer

GitHubmgeeky/sharpwebserver

Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality

lateral-movementred-teaming
2883 years ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6394 years ago
HTTP-Shell preview

HTTP-Shell

GitHubjoelgmsec/http-shell

Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

command-and-controlpayload-generationpenetration-testing+2
2441 month ago
Burp2Malleable preview

Burp2Malleable

GitHubcodextf2/burp2malleable

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

command-and-controlids-ips-evasionpayload-development+2
4183 years ago
skyhook preview

skyhook

GitHubblackhillsinfosec/skyhook

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

data-exfiltrationids-ips-evasionred-teaming+1
2882 years ago
sshimpanzee preview

sshimpanzee

GitHublexfo/sshimpanzee

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

command-and-controldns-analysisnetwork-security+4
2941 year ago
pipe-intercept preview

pipe-intercept

GitHubgabriel-sztejnworcel/pipe-intercept

Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools

penetration-testingred-teamingweb-proxies-interception
30411 months ago
QueenSono preview

QueenSono

GitHubariary/queensono

Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)

command-and-controldata-exfiltrationnetwork-security+2
1683 months ago
Arecibo preview

Arecibo

GitHubtarlogicsecurity/arecibo

Endpoint for Out-of-Band Exfiltration (DNS & HTTP)

data-exfiltrationdns-analysisinformation-gathering+2
947 years ago
LightMe preview

LightMe

GitHubsafebuffer/lightme

HTTP Server serving obfuscated Powershell Scripts/Payloads

command-and-controlpayload-developmentpayload-generation+2
955 years ago
HttpRemotingObjRefLeak preview

HttpRemotingObjRefLeak

GitHubcodewhitesec/httpremotingobjrefleak

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

code-analysisexploitationpayload-development+4
922 years ago
bbs preview

bbs

GitHubsynacktiv/bbs

bbs is a router for SOCKS and HTTP proxies. It exposes a SOCKS5 (or HTTP CONNECT) service and forwards incoming requests to proxies or chains of…

network-securitypenetration-testingred-teaming+2
991 month ago
cc-ddos preview

cc-ddos

GitHubnayumidev/cc-ddos

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

penetration-testingred-teamingweb-application-exploitation
811 year ago
SharePointDumper preview

SharePointDumper

GitHubzh54321/sharepointdumper

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

authenticationcloud-securitydata-exfiltration+7
1677 months ago
cowitness preview

cowitness

GitHubstolenusername/cowitness

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

dns-analysisinformation-gatheringpenetration-testing+3
1252 years ago
ReverseHttp preview

ReverseHttp

GitHubd4vinci/reversehttp

Python backdoor that uses http post/get requests to communicate

command-and-controlpayload-developmentpenetration-testing+3
4210 years ago
Fenrir preview

Fenrir

GitHubnccgroup/fenrir

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

command-and-controllateral-movementpenetration-testing+3
6711 years ago
Previous123…9Next