Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
200 results
SharpDPAPI preview

SharpDPAPI

GitHubghostpack/sharpdpapi

SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.

data-exfiltrationencryption-decryption-toolsexploitation+4
1.4k
2 years ago
Koppeling preview

Koppeling

GitHubmonoxgas/koppeling

Adaptive DLL hijacking / dynamic export forwarding

binary-exploitationexploitationpayload-development+1
8196 years ago
RedCloud-OS preview

RedCloud-OS

GitHubredteamoperations/redcloud-os

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

adversarial-attackcloud-securityeducation+2
6776 months ago
WindowsElevation preview

WindowsElevation

GitHubal1ex/windowselevation

Windows Elevation(持续更新)

exploitationpenetration-testingpost-exploitation+3
6674 years ago
DEFCON-31-Syscalls-Workshop preview

DEFCON-31-Syscalls-Workshop

GitHubvirtualalllocex/defcon-31-syscalls-workshop

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

educationlabs-practicepayload-development+2
7741 year ago
cs2modrewrite preview

cs2modrewrite

GitHubthreatexpress/cs2modrewrite

Convert Cobalt Strike profiles to modrewrite scripts

command-and-controlids-ips-evasionnetwork-security+3
6073 years ago
Kerbeus-BOF preview

Kerbeus-BOF

GitHubralfhacker/kerbeus-bof

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

authenticationcommand-and-controlexploitation+6
6099 months ago
hershell preview

hershell

GitHubsysdream/hershell

Hershell is a simple TCP reverse shell written in Go.

command-and-controlexploitationpayload-generation+5
5297 years ago
CallStackSpoofer preview

CallStackSpoofer

GitHubwithsecurelabs/callstackspoofer

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

adversarial-attackids-ips-evasionpost-exploitation+1
5931 year ago
dref preview

dref

GitHubreverseclabs/dref

DNS Rebinding Exploitation Framework

dns-analysisexploitationiot-security+3
4945 years ago
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

payload-developmentpost-exploitationred-teaming+1
5132 years ago
RedTeam_toolkit preview

RedTeam_toolkit

GitHubsignorrayan/redteam_toolkit

Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.

exploitationinformation-gatheringpassword-attacks+5
5726 months ago
CallstackSpoofingPOC preview

CallstackSpoofingPOC

GitHubpard0p/callstackspoofingpoc

C++ self-Injecting dropper based on various EDR evasion techniques.

adversarial-attackids-ips-evasionpayload-development+1
4422 years ago
tap preview

tap

GitHubtrustedsec/tap

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

command-and-controlpenetration-testing-frameworkspersistence-mechanisms+3
5043 years ago
uC_mousejack preview

uC_mousejack

GitHubinsecurityofthings/uc_mousejack

Mousejack for ATmega32u4

bluetooth-securityembedded-systems-securityhardware-hacking+4
2563 years ago
AV-EDR-Killer preview

AV-EDR-Killer

GitHubxm0kht4r/av-edr-killer

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

command-and-controlexploitationids-ips-evasion+5
2987 months ago
GoPurple preview

GoPurple

GitHubsh4hin/gopurple

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

defensive-toolseducationexploitation+6
4965 years ago
redpill preview

redpill

GitHubr00t-3xp10it/redpill

Assist reverse tcp shells in post-exploration tasks

defensive-toolsinformation-gatheringlateral-movement+6
21810 months ago
Previous1…678…12Next