Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
Salsa-tools preview

Salsa-tools

GitHubhackplayers/salsa-tools

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

command-and-controlencryption-decryption-toolsexploitation+7
590
6 years ago
hershell preview

hershell

GitHubsysdream/hershell

Hershell is a simple TCP reverse shell written in Go.

command-and-controlexploitationpayload-generation+5
5317 years ago
r2rs preview

r2rs

GitHubhakkuri01/r2rs

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

command-and-controlexploitationpenetration-testing+3
14 months ago
meterssh preview

meterssh

GitHubtrustedsec/meterssh

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

command-and-controlexploitationpayload-development+4
5309 years ago
EXOCET-AV-Evasion preview

EXOCET-AV-Evasion

GitHubtanc7/exocet-av-evasion

EXOCET - AV-evading, undetectable, payload delivery tool

command-and-controlcryptographyeducation+9
8414 years ago
KittyStager preview

KittyStager

GitHubenelg52/kittystager

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

command-and-controleducationencryption-decryption-tools+6
2263 years ago
gmailc2 preview

gmailc2

GitHubmachine1337/gmailc2

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

command-and-controleducationpayload-generation+4
4891 year ago
ROPInjector preview

ROPInjector

GitHubgpoulios/ropinjector

Patching ROP-encoded shellcodes into PEs

binary-analysisbinary-exploitationexploitation+7
1868 years ago
CVE-2021-3156-Baron-Samedit preview

CVE-2021-3156-Baron-Samedit

GitHubtheleopard65/cve-2021-3156-baron-samedit

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

binary-exploitationcontainer-securityeducation+5
16 months ago
RemoteTLSCallbackInjection preview

RemoteTLSCallbackInjection

GitHubmaldev-academy/remotetlscallbackinjection

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

binary-exploitationeducationlabs-practice+1
2912 years ago
ASLRay preview

ASLRay

GitHubcryptolok/aslray

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying

binary-exploitationexploitationexploit-frameworks+4
3103 years ago
Exploit-Development preview

Exploit-Development

GitHubwetw0rk/exploit-development

CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002

exploitationexploit-frameworkspayload-development+3
836 months ago
CVE-2021-27965 preview

CVE-2021-27965

GitHubjeromeyoung/cve-2021-27965

Proof of concept for CVE-2021-27965 (Stack-based Buffer Overflow)

binary-exploitationexploitationpayload-development+2
4 years ago
astroid preview

astroid

GitHubm4sc3r4n0/astroid

ASTROID v 1.2 bypass most A.V softwares

educationexploit-frameworkspayload-generation+2
879 years ago