Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
yara-ttd preview

yara-ttd

GitHubairbus-cert/yara-ttd

Use YARA rules on Time Travel Debugging traces

binary-analysisdynamic-analysis-sandboxingmalware-analysis+3
97
3 years ago
msf_shellcode_analysis preview

msf_shellcode_analysis

GitHubyo-yo-yo-jbo/msf_shellcode_analysis

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

binary-analysiseducationmalware-analysis+3
291 month ago
AsmLdr preview

AsmLdr

GitHub0xninjacyclone/asmldr

Dynamic shellcode loader with sophisticated evasion capabilities

ids-ips-evasionpayload-developmentpayload-generation+3
34610 months ago
NullGate preview

NullGate

GitHub0xsch1zo/nullgate

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

adversarial-attackencryption-decryption-toolspayload-development+3
1681 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubfaithtiannn/cve-2025-55182

CVE-2025-55182漏洞检测工具

command-and-controlexploitationpayload-development+5
27 months ago
NyxInvoke preview

NyxInvoke

GitHubblacksnufkin/nyxinvoke

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

command-and-controlexploitationids-ips-evasion+6
2421 year ago
dicerosbicornis preview

dicerosbicornis

GitHubmaldevel/dicerosbicornis

A fully featured Windows backdoor that uses email as a C&C server

command-and-controldata-exfiltrationencryption-decryption-tools+5
169 years ago
chakra-exploit-framework preview

chakra-exploit-framework

GitHubntdelta/chakra-exploit-framework

Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567

binary-exploitationeducationexploit-frameworks+6
11 year ago
CVE-2025-55182-POC preview

CVE-2025-55182-POC

GitHubluoqichen/cve-2025-55182-poc

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

command-and-controlexploitationpayload-development+5
5 months ago
nocturne preview

nocturne

GitHubnodiuus/nocturne

A bin2bin code virtualizer for x86-64 PE's

binary-analysisbinary-exploitationexploitation+5
1742 months ago
CVE-2023-38035-MobileIron-RCE preview

CVE-2023-38035-MobileIron-RCE

GitHubmind2hex/cve-2023-38035-mobileiron-rce

Script to exploit CVE-2023-38035

exploitationpenetration-testingreconnaissance+3
12 years ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubfkshield/cve-2025-5548

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

binary-exploitationdynamic-analysis-sandboxingeducation+9
1 month ago
themida-unmutate preview

themida-unmutate

GitHubergrelet/themida-unmutate

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

binary-analysisbinary-exploitationmalware-analysis+3
3902 years ago
aether preview

aether

GitHub0xsp-srd/aether

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

binary-analysiscommand-and-controldigital-forensics+7
581 month ago
cve-2023-42115 preview

cve-2023-42115

GitHubkirinse/cve-2023-42115

Python-based exploit and reverse shell payload generator for CVE-2023-42115, featuring scan and exploit modes with cross-platform payload creation.

exploitationpayload-developmentpayload-generation+3
91 year ago
JBWPer preview

JBWPer

GitHubim-hanzou/jbwper

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4061 - JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationshellcode+2
52 years ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubalberto-galindo/cve-2025-5548

Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

binary-exploitationdebuggerseducation+8
5 months ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
63 months ago
Previous12Next