Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
EternalBlueC preview

EternalBlueC

GitHubbhassani/eternalbluec

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

binary-exploitationeducationexploitation+7
618
9 days ago
BokuLoader preview

BokuLoader

GitHubboku7/bokuloader

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

binary-analysisexploit-frameworkspayload-development+3
1.4k2 years ago
ShellGhost preview

ShellGhost

GitHublem0nsec/shellghost

A memory-based evasion technique which makes shellcode invisible from process start to end.

binary-analysisencryption-decryption-toolsexploitation+4
1.2k2 years ago
nano preview

nano

GitHubs0md3v/nano

Nano is a family of PHP web shells which are code golfed for stealth.

command-and-controlpayload-generationpenetration-testing+3
4496 years ago
MorphAES preview

MorphAES

GitHubcryptolok/morphaes

IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…

binary-exploitationexploitationids-ips-evasion+4
3244 years ago
p3-loader preview

p3-loader

GitHuborange-cyberdefense/p3-loader

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

binary-exploitationdefensive-toolseducation+8
2132 months ago
DNS-Persist preview

DNS-Persist

GitHub0x09al/dns-persist

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

command-and-controldns-analysispayload-generation+5
2078 years ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubwearehackers160/cve-2026-48907

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

exploitationpayload-generationpenetration-testing+3
3 months ago
Partial-deobfuscated-sc-from-HackingTeam-Malware.- preview

Partial-deobfuscated-sc-from-HackingTeam-Malware.-

GitHubspiralbl0ck/partial-deobfuscated-sc-from-hackingteam-malware.-

This repo stores necessary files for the analysis blog which will come soon

binary-analysiseducationmalware-analysis+3
12 years ago
Conflicker_analysis_scripts preview

Conflicker_analysis_scripts

GitHubthunderstrike9090/conflicker_analysis_scripts

Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067

binary-analysisexploitationmalware-analysis+3
17 years ago
Rig-Exploit-for-CVE-2018-8174 preview

Rig-Exploit-for-CVE-2018-8174

GitHuborf53975/rig-exploit-for-cve-2018-8174

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

command-and-controlexploitationmalware-analysis+3
8 years ago
OffensiveRust preview

OffensiveRust

GitHubtrickster0/offensiverust

Rust Weaponization for Red Team Engagements.

binary-exploitationcommand-and-controleducation+9
3.0k3 years ago
avet preview

avet

GitHubgovolution/avet

AntiVirus Evasion Tool

adversarial-attackeducationencryption-decryption-tools+8
1.8k1 year ago
SysWhispers3 preview

SysWhispers3

GitHubklezvirus/syswhispers3

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

defensive-toolsexploitationids-ips-evasion+5
1.7k2 years ago
ZSC preview

ZSC

GitHubowasp/zsc

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

encryption-decryption-toolsexploit-frameworkspayload-generation+5
6522 years ago
twittor preview

twittor

GitHubpaulsec/twittor

A fully featured backdoor that uses Twitter as a C&C server

command-and-controlexploitationpayload-development+4
81111 years ago
DEFCON-31-Syscalls-Workshop preview

DEFCON-31-Syscalls-Workshop

GitHubvirtualalllocex/defcon-31-syscalls-workshop

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

educationlabs-practicepayload-development+2
7841 year ago
quasibot preview

quasibot

GitHubsmaash/quasibot

complex webshell manager, quasi-http botnet.

command-and-controlexploitationinformation-gathering+6
28411 years ago
Previous123Next