Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
100 results
Ivy preview
Archived

Ivy

GitHuboptiv/ivy

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

exploitationpayload-developmentpayload-generation+4
743
3 years ago
CVE-2018-6537.RCE preview
Archived

CVE-2018-6537.RCE

GitHubdamariion/cve-2018-6537.rce

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code…

binary-exploitationexploitationpayload-generation+4
5 months ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k2 days ago
VX-API preview

VX-API

GitHubvxunderground/vx-api

Collection of various malicious functionality to aid in malware development

anti-botbinary-analysiscryptography+5
1.9k3 years ago
avet preview

avet

GitHubgovolution/avet

AntiVirus Evasion Tool

adversarial-attackeducationencryption-decryption-tools+8
1.8k1 year ago
twittor preview

twittor

GitHubpaulsec/twittor

A fully featured backdoor that uses Twitter as a C&C server

command-and-controlexploitationpayload-development+4
80911 years ago
maldev-for-dummies preview

maldev-for-dummies

GitHubchvancooten/maldev-for-dummies

A workshop about Malware Development

educationexploitationlabs-practice+4
1.8k3 years ago
laZzzy preview

laZzzy

GitHubcapt-meelo/lazzzy

Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

shellcodeshellcode-generation
5053 years ago
quasibot preview

quasibot

GitHubsmaash/quasibot

complex webshell manager, quasi-http botnet.

command-and-controlexploitationinformation-gathering+6
28411 years ago
gdog preview

gdog

GitHubmaldevel/gdog

A fully featured Windows backdoor that uses Gmail as a C&C server

command-and-controlpayload-generationpost-exploitation+2
5079 years ago
Exploits + Shellcode + GHDB preview

Exploits + Shellcode + GHDB

GitLabexploit-database/exploitdb

exploitdb // The official Exploit-Database repository

curated-resourceseducationexploitation+7
2583 days ago
RecycledInjector preview

RecycledInjector

GitHubflorylsk/recycledinjector

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

privilege-escalationshellcodeshellcode-generation
2663 years ago
AirBorne-PoC preview

AirBorne-PoC

GitHubekomssavior/airborne-poc

poc for CVE-2025-24252 & CVE-2025-24132

binary-exploitationcommand-and-controlexploitation+6
1648 months ago
SharpZipRunner preview

SharpZipRunner

GitHubjfmaes/sharpziprunner

Executes position independent shellcode from an encrypted zip

exploitationpayload-developmentpayload-generation+3
3035 years ago
acheron preview

acheron

GitHubf1zm0/acheron

indirect syscalls for AV/EDR evasion in Go assembly

payload-developmentred-teamingshellcode
3933 years ago
SharpProxyLogon preview

SharpProxyLogon

GitHubflangvik/sharpproxylogon

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

exploitationpayload-developmentpost-exploitation+3
2475 years ago
CVE-2016-6366 preview

CVE-2016-6366

GitHubrisksense-ops/cve-2016-6366

Public repository for improvements to the EXTRABACON exploit

binary-analysisexploitationexploit-frameworks+8
1639 years ago
themida-unmutate preview

themida-unmutate

GitHubergrelet/themida-unmutate

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.

binary-analysisbinary-exploitationmalware-analysis+3
3902 years ago
Previous123456Next