Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
289 results
Anti_suspend preview

Anti_suspend

GitHubgmh5225/anti_suspend

Shellcode-based process protection that prevents thread suspension, blocks debugger attach, masks hardware breakpoints, and hides threads from…

defensive-toolsreverse-engineeringshellcode
53 years ago
Java-Shellcode-Loader preview

Java-Shellcode-Loader

GitHubyzddmr6/java-shellcode-loader

基于Java实现的Shellcode加载器

payload-developmentpenetration-testingred-teaming+1
4142 years ago
SleepyCrypt preview

SleepyCrypt

GitHubsolomonsklash/sleepycrypt

A shellcode function to encrypt a running process image when sleeping.

ids-ips-evasionpayload-developmentred-teaming+1
3384 years ago
OneDriveUpdaterSideloading preview

OneDriveUpdaterSideloading

GitHubchoisg/onedriveupdatersideloading

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

adversarial-attackpayload-developmentred-teaming+1
1023 years ago
Lastenzug preview

Lastenzug

GitHubcodewhitesec/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

command-and-controlids-ips-evasionpayload-development+3
2343 years ago
FlavorTown preview

FlavorTown

GitHubwra7h/flavortown

Various ways to execute shellcode

payload-developmentpost-exploitationred-teaming+1
5132 years ago
SharpWhispers preview

SharpWhispers

GitHubsecforce/sharpwhispers

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

ids-ips-evasionpayload-developmentpost-exploitation+2
1123 years ago
Bitmancer preview

Bitmancer

GitHubzimawhit3/bitmancer

Nim Library for Offensive Security Development

binary-analysisids-ips-evasionpayload-development+4
2002 years ago
DynamicDotNet preview

DynamicDotNet

GitHubbohops/dynamicdotnet

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

curated-resourceseducationmalware-analysis+4
1452 years ago
Split preview

Split

GitHubkudaes/split

Apply a divide and conquer approach to bypass EDRs

adversarial-attackids-ips-evasionpayload-development+3
2872 years ago
ntqueueapcthreadex-ntdll-gadget-injection preview

ntqueueapcthreadex-ntdll-gadget-injection

GitHublloydlabs/ntqueueapcthreadex-ntdll-gadget-injection

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

adversarial-attackids-ips-evasionpayload-development+3
2673 years ago
D1rkLdr preview

D1rkLdr

GitHubsaadahla/d1rkldr

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

ids-ips-evasionpayload-developmentred-teaming+1
3233 years ago
Lastenzug preview

Lastenzug

GitHubps1337/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

ids-ips-evasionpayload-developmentpost-exploitation+3
264 years ago
OffensiveCpp preview

OffensiveCpp

GitHublsecqt/offensivecpp

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

adversarial-attackcurated-resourcesexploitation+6
7691 year ago
EATGuard preview

EATGuard

GitHubconnormcgarr/eatguard

Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)

binary-exploitationdefensive-toolsshellcode
1143 years ago
msf_shellcode_analysis preview

msf_shellcode_analysis

GitHubyo-yo-yo-jbo/msf_shellcode_analysis
binary-analysiseducationmalware-analysis+3
291 month ago
DEFCON-31-Syscalls-Workshop preview

DEFCON-31-Syscalls-Workshop

GitHubvirtualalllocex/defcon-31-syscalls-workshop

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

educationlabs-practicepayload-development+2
7741 year ago
Percino preview

Percino

GitHubtunnelgre/percino

Evasive Golang Loader

adversarial-attackcommand-and-controlids-ips-evasion+4
1362 years ago
Previous12…17Next