Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
promptfoo preview

promptfoo

GitHubpromptfoo/promptfoo

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and…

adversarial-attackai-securitydevsecops+5
25.0k
1h 44m ago
ezEmu preview

ezEmu

GitHubjwillyamz/ezemu

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)

adversarial-attackdefensive-toolseducation+3
1093 years ago
T-MAP preview

T-MAP

GitHubpwnhyo/t-map

Trajectory-aware evolutionary search framework for red-teaming LLM agents over MCP servers, generating adversarial prompts to map vulnerability…

adversarial-attackai-securitymachine-learning+3
185 months ago
CVE-2025-32432-PoC preview

CVE-2025-32432-PoC

GitHubezramansor/cve-2025-32432-poc

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

adversarial-attackexploitationpayload-generation+3
1 month ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k4 days ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k18h 21m ago
modelscan preview

modelscan

GitHubprotectai/modelscan

Protection against Model Serialization Attacks

adversarial-attackai-securitydefensive-tools+5
7736 months ago
VehApiResolve preview

VehApiResolve

GitHubrad9800/vehapiresolve

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

adversarial-attackpayload-developmentred-teaming
1184 years ago
CanaryHunter preview

CanaryHunter

GitHubc0axx/canaryhunter

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

adversarial-attackcloud-infrastructure-securityconfiguration-auditing+4
1373 years ago
caldera preview

caldera

GitHubapache/caldera

Automated Adversary Emulation Platform

adversarial-attackcommand-and-controlctf+7
7.2k13 days ago
red-kube preview

red-kube

GitHublightspin-tech/red-kube

Red Team K8S Adversary Emulation Based on kubectl

adversarial-attackcloud-securitycommand-and-control+6
8285 years ago
Dirty-Vanity preview

Dirty-Vanity

GitHubdeepinstinct/dirty-vanity

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

adversarial-attackexploitationpayload-development+4
6783 years ago
unhook-bof preview

unhook-bof

GitHubrsmudge/unhook-bof

Remove API hooks from a Beacon process.

adversarial-attackids-ips-evasionpost-exploitation+1
2834 years ago
UnhookingPatch preview

UnhookingPatch

GitHubsaadahla/unhookingpatch

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

adversarial-attackids-ips-evasionpayload-development+2
3063 years ago
CrystalPotato preview

CrystalPotato

GitHubricardojoserf/crystalpotato

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

adversarial-attackexploitationpenetration-testing+3
11817 days ago
LibTP preview

LibTP

GitHubrasta-mouse/libtp

Crystal Palace library for proxying Nt API calls via the Threadpool

adversarial-attackids-ips-evasionpayload-development+2
10710 months ago
LibTP_Gadget preview

LibTP_Gadget

GitHubsaerxcit/libtp_gadget

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

adversarial-attackids-ips-evasionpayload-development+3
2310 months ago
aco-prompt-shield preview

aco-prompt-shield

GitHubaniketkarne/aco-prompt-shield

Stop prompt injection attacks before they reach your LLM — zero API costs, runs entirely locally, integrates in 2 minutes. Prompt injection is the…

adversarial-attackai-securityanomaly-detection+3
42 months ago
Previous1234Next