Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
909 results
AI-FILE preview

AI-FILE

GitHubkyle41111/ai-file

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

ai-securitycommand-and-controldata-exfiltration+7
132 days ago
mediawiki-CVE-2026-100382 preview

mediawiki-CVE-2026-100382

GitHubnth347/mediawiki-cve-2026-100382

Docker lab reproducing CVE-2026-100382: unauthenticated argument-injection RCE in MediaWiki ExternalData's #get_program_data, with PoC payloads and…

command-and-controleducationexploitation+4
36 days ago
httpx preview

httpx

GitHubmythicc2profiles/httpx

Configurable, Community driven, HTTP C2 Profile

command-and-controldefensive-toolsencryption-decryption-tools+5
282 months ago
METIS preview

METIS

GitHubk3ystr0k3r/metis

Modular Python exploitation framework with a Metasploit-style console, auto-registering Exploit and Auxiliary modules, tri-state checks, and multiple…

command-and-controlctfeducation+9
33 days ago
Koi preview

Koi

GitHubb3rt1ng/koi

Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

command-and-controlids-ips-evasionlateral-movement+9
274 days ago
redStackPRO preview

redStackPRO

GitHubdevzero-security/redstackpro

A canvas for red team infrastructure and cyber ranges. Compose a topology, export runnable Terraform and Ansible, and deploy it yourself. Your cloud…

cloud-infrastructure-securitycloud-securitycommand-and-control+8
614 days ago
CVE-2026-44011-poc preview

CVE-2026-44011-poc

GitHubdennisdgr/cve-2026-44011-poc

Authenticated Craft CMS RCE PoC for CVE-2026-44011

command-and-controlexploitationpenetration-testing+5
6 days ago
RedTeamSimmer preview

RedTeamSimmer

GitHubbreachsimrange/redteamsimmer

Web-based adversary emulation platform that orchestrates Atomic Red Team tests across Windows endpoints via Go agents, with MITRE ATT&CK mapping, APT…

adversarial-attackcommand-and-controldefensive-tools+7
81 month ago
Red-Team-GOAD-Lab-Proxmox preview

Red-Team-GOAD-Lab-Proxmox

GitHubpho5nix/red-team-goad-lab-proxmox

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

adversarial-attackcommand-and-controldefensive-tools+7
287 days ago
Harald preview

Harald

GitHubgmh5225/harald

An in-memory minimal CPU for agnostic on-the-fly protocols creation

command-and-controlexploitationids-ips-evasion+6
1 year ago
waybend preview

waybend

GitHubprinciplebreach/waybend

Self-hosted SSRF redirect, payload, callback, and DNS workbench

command-and-controldns-analysisinformation-gathering+9
521 days ago
Hexestra preview

Hexestra

GitHubabsllk/hexestra

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

ai-securitycommand-and-controlinformation-gathering+7
822 days ago
flipper-mcp preview

flipper-mcp

GitHubroostercoopllc/flipper-mcp

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.

ai-securitybluetooth-securitycommand-and-control+9
277 months ago
CVE-2023-49070 preview

CVE-2023-49070

GitHubbardlaudian/cve-2023-49070

Python PoC for Apache OFBiz CVE-2023-49070: auth-bypass on /webtools/control/xmlrpc plus ysoserial gadget chain to achieve pre-auth deserialization…

command-and-controldefensive-toolsexploitation+5
9 days ago
CVE-2026-93349-frictionless-command-injection preview

CVE-2026-93349-frictionless-command-injection

GitHubsaiteja-erukude/cve-2026-93349-frictionless-command-injection

Proof-of-concept for CVE-2026-93349, an OS command injection in Frictionless <= 5.20.0rc1 explore CLI via malicious Data Package descriptor paths.

command-and-controleducationexploitation+3
10 days ago
GitHub-gato preview

GitHub-gato

GitHubgmh5225/github-gato

GitHub Self-Hosted Runner Enumeration and Attack Tool

command-and-controldefensive-toolsexploitation+6
13 years ago
rcekit preview

rcekit

GitHubkabiri-labs/rcekit

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

command-and-controlexploitationfuzzing+8
245 days ago
pentest-harness preview

pentest-harness

GitHubs1n6h/pentest-harness

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

ai-securitycommand-and-controlctf+7
40023 days ago
Previous12…51Next