Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
296 results
CVE-2025-34096 preview

CVE-2025-34096

GitHubthemalwareguardian/cve-2025-34096

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

binary-exploitationeducationexploitation+6
5 months ago
BOF_RunPe preview

BOF_RunPe

GitHubntdallas/bof_runpe

BOF to run PE in Cobalt Strike Beacon without console creation

memory-forensicspost-exploitationred-teaming+1
2009 months ago
CVE-2021-40449 preview

CVE-2021-40449

GitHubhakivvi/cve-2021-40449

Windows LPE exploit for CVE-2021-40449, a use-after-free in win32kfull!GreResetDCInternal, leveraging token leaking, kernel gadget abuse, and…

binary-exploitationexploitationmemory-forensics+4
464 years ago
CVE-2024-1065 preview

CVE-2024-1065

GitHubkuzeyardabulut/cve-2024-1065

Proof-of-concept exploit for CVE-2024-1065, demonstrating page cache exploitation via a use-after-free in the ARM Mali GPU kernel driver to achieve…

binary-exploitationexploitationmemory-forensics+4
42 months ago
merlin preview

merlin

GitHubne0nd0g/merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

command-and-controldata-exfiltrationexploit-frameworks+10
5.6k1 year ago
OffensiveNim preview

OffensiveNim

GitHubbyt3bl33d3r/offensivenim

My experiments in weaponizing Nim (https://nim-lang.org/)

binary-exploitationcode-analysiscommand-and-control+8
3.1k2 years ago
Shhhloader preview

Shhhloader

GitHubicyguider/shhhloader

Syscall Shellcode Loader (Work in Progress)

shellcode
1.3k2 years ago
the-backdoor-factory preview

the-backdoor-factory

GitHubsecretsquirrel/the-backdoor-factory

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

binary-exploitationexploitationmalware-analysis+6
3.4k2 years ago
VX-API preview

VX-API

GitHubvxunderground/vx-api

Collection of various malicious functionality to aid in malware development

anti-botbinary-analysiscryptography+5
1.9k3 years ago
Nimcrypt2 preview

Nimcrypt2

GitHubicyguider/nimcrypt2

.NET, PE, & Raw Shellcode Packer/Loader Written in Nim

binary-analysisdefensive-toolsencryption-decryption-tools+6
8254 years ago
EternalBlueC preview

EternalBlueC

GitHubbhassani/eternalbluec

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

binary-exploitationeducationexploitation+7
6164 days ago
meterssh preview

meterssh

GitHubtrustedsec/meterssh

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

command-and-controlexploitationpayload-development+4
5299 years ago
SharpSploit preview

SharpSploit

GitHubcobbr/sharpsploit

SharpSploit is a .NET post-exploitation library written in C#

command-and-controlexploitationinformation-gathering+9
1.9k5 years ago
Invisi-Shell preview

Invisi-Shell

GitHubomerya/invisi-shell

Hide your Powershell script in plain sight. Bypass all Powershell security features

defensive-toolsexploitationids-ips-evasion+9
1.3k7 years ago
hershell preview

hershell

GitHubsysdream/hershell

Hershell is a simple TCP reverse shell written in Go.

command-and-controlexploitationpayload-generation+5
5297 years ago
RedPeanut preview

RedPeanut

GitHubb4rtik/redpeanut

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

command-and-controlexploit-frameworkspayload-generation+7
3306 years ago
OffensiveCpp preview

OffensiveCpp

GitHublsecqt/offensivecpp

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

adversarial-attackcurated-resourcesexploitation+6
7711 year ago
frostbyte preview

frostbyte

GitHubpwn1sher/frostbyte

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

shellcodeshellcode-generation
3844 years ago
Previous12…17Next