Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
841 results
CobaltStrike-Toolset preview

CobaltStrike-Toolset

GitHubqax-a-team/cobaltstrike-toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

command-and-controlexploit-frameworkslateral-movement+8
593
7 years ago
ASLRay preview

ASLRay

GitHubcryptolok/aslray

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying

binary-exploitationexploitationexploit-frameworks+4
3103 years ago
MsfMania preview

MsfMania

GitHublepotekil/msfmania

Python AV Evasion Tools

binary-analysiseducationencryption-decryption-tools+9
51610 months ago
frostbyte preview

frostbyte

GitHubpwn1sher/frostbyte

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

shellcodeshellcode-generation
3844 years ago
bluffy preview

bluffy

GitHubpreemptdev/bluffy

Convert shellcode into :sparkles: different :sparkles: formats!

ids-ips-evasionpayload-generationshellcode+1
3563 years ago
ropr preview

ropr

GitHubben-lichtman/ropr

A blazing fast™ multithreaded ROP Gadget finder. ropper / ropgadget alternative (currently x86 only)

binary-analysisexploitationreverse-engineering+1
5564 months ago
Voidgate preview

Voidgate

GitHubvxcrypt0r/voidgate

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

adversarial-attackdebuggersids-ips-evasion+3
5982 years ago
AsmLdr preview

AsmLdr

GitHub0xninjacyclone/asmldr

Dynamic shellcode loader with sophisticated evasion capabilities

ids-ips-evasionpayload-developmentpayload-generation+3
34611 months ago
Dirty-Vanity preview

Dirty-Vanity

GitHubdeepinstinct/dirty-vanity

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

adversarial-attackexploitationpayload-development+4
6783 years ago
canisrufus preview

canisrufus

GitHubmaldevel/canisrufus

A stealthy Python based Windows backdoor that uses Github as a command and control server

command-and-controlpayload-generationpost-exploitation+2
2659 years ago
AlanFramework preview

AlanFramework

GitHubenkomio/alanframework

A C2 post-exploitation framework

command-and-controlencryption-decryption-toolslateral-movement+7
4862 years ago
xsser preview

xsser

GitHubvarbaek/xsser

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

exploitationpayload-developmentpenetration-testing+3
4236 years ago
inject-assembly preview

inject-assembly

GitHubkyleavery/inject-assembly

Inject .NET assemblies into an existing process

exploitationpost-exploitationred-teaming+1
5094 years ago
Armor preview

Armor

GitHubtokyoneon/armor

Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

encryption-decryption-toolspayload-developmentpayload-generation+3
2777 years ago
phantom-frida preview

phantom-frida

GitHubtheqmaks/phantom-frida

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

android-securitybinary-analysisdynamic-analysis-sandboxing+7
3731 month ago
CallbackHell preview

CallbackHell

GitHubly4k/callbackhell

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

binary-exploitationexploitationpayload-development+4
4834 years ago
gmailc2 preview

gmailc2

GitHubmachine1337/gmailc2

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

command-and-controleducationpayload-generation+4
49011 months ago
BadAssMacros preview

BadAssMacros

GitHubinf0secrabbit/badassmacros

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

exploit-frameworkspayload-generationred-teaming+1
4445 years ago
Previous1…101112…47Next