Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
48 results
AutoSploit preview

AutoSploit

GitHubnullarray/autosploit

Automated Mass Exploiter

command-and-controlexploit-frameworksinformation-gathering+5
5.3k
6 years ago
abaddon preview
Archived

abaddon

GitHubwavestone-cdt/abaddon

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

cloud-infrastructure-securitycommand-and-controlexploit-frameworks+5
3313 years ago
Kautilya preview

Kautilya

GitHubsamratashok/kautilya

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

command-and-controldata-exfiltrationhardware-iot-security+6
8719 years ago
Quasar preview
Archived

Quasar

GitHubquasar/quasar

Remote Administration Tool for Windows

command-and-controlpenetration-testingpost-exploitation+2
9.9k2 years ago
mcp-server-attestation preview

mcp-server-attestation

GitHubstudiomeyer-io/mcp-server-attestation

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

code-analysiscommand-and-controlcryptography+3
6 days ago
python-pentesting preview

python-pentesting

GitHubustayready/python-pentesting

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

cloud-securitycommand-and-controleducation+6
2196 years ago
SSTImap preview

SSTImap

GitHubvladko312/sstimap

Automatic SSTI detection tool with interactive interface

code-analysiscommand-and-controldynamic-code-analysis+6
1.6k13 days ago
netrat preview

netrat

GitHubroccomuso/netrat

Damn easy multiplatform Node.js RAT generator.

command-and-controlexploitationpayload-generation+1
325 years ago
ShellPop preview

ShellPop

GitHub0x00-0x00/shellpop

Pop shells like a master.

command-and-controlencryption-decryption-toolsexploitation+6
1.5k7 years ago
imaginaryC2 preview

imaginaryC2

GitHubfelixweyne/imaginaryc2

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

command-and-controldigital-forensicsdynamic-analysis-sandboxing+5
4463 years ago
pace preview
Archived

pace

GitHubtypetrait/pace

Remote Access Tool for Windows.

command-and-controlpenetration-testingpost-exploitation+3
823 years ago
Lime-RAT preview
Archived

Lime-RAT

GitHubnyan-x-cat/lime-rat

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

command-and-controlcryptographydata-exfiltration+7
1.1k7 years ago
SkillsGuard preview

SkillsGuard

GitHubteycir/skillsguard

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

ai-securitycode-analysiscommand-and-control+8
152 months ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
21 month ago
CVE-2023-46805 preview

CVE-2023-46805

GitHubw2xim3/cve-2023-46805

CVE-2023-46805 Ivanti POC RCE - Ultra fast scanner.

command-and-controleducationexploitation+3
22 years ago
cve-2025-3248 preview

cve-2025-3248

GitHubbambooqj/cve-2025-3248

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

command-and-controlexploitationpenetration-testing+3
110 months ago
CVE-2021-21315 preview

CVE-2021-21315

GitHubg01d3nw01f/cve-2021-21315

rust noob tried write easy exploit code with rust lang

command-and-controleducationexploitation+3
14 years ago
Codecepticon preview
Archived

Codecepticon

GitHubaccenture/codecepticon

.NET/PowerShell/VBA Offensive Security Obfuscator

code-analysiscommand-and-controlids-ips-evasion+5
5262 years ago
Previous123Next