Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
132 results
EasY_HaCk preview

EasY_HaCk

GitHubsabri-zaki/easy_hack

Hack the World using Termux

exploit-frameworksinformation-gatheringnetwork-mapping+4
2.5k1 year ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

cloud-securitycommand-and-controlencryption-decryption-tools+6
3910 days ago
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

api-securityapi-security-testingcrawler+12
38.4k2 days ago
Evil-Droid preview

Evil-Droid

GitHubm4sc3r4n0/evil-droid

Framework to create, generate, and embed APK payloads for Android penetration testing, leveraging Metasploit for exploitation and Apktool for…

android-securityeducationexploit-frameworks+4
1.1k8 years ago
CyberStrike preview

CyberStrike

GitHubcyberstrikeus/cyberstrike

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

ai-securitycloud-securityeducation+9
2.6k0 days ago
PAKURI-THON preview

PAKURI-THON

GitHub01rabbit/pakuri-thon

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

command-and-controlexploit-frameworksinformation-gathering+7
284 years ago
LDAPFragger preview

LDAPFragger

GitHubfox-it/ldapfragger

C2 tool routing Cobalt Strike beacon data over LDAP user attributes for stealthy command-and-control in segmented networks.

command-and-controlexploit-frameworkspayload-development+2
1966 years ago
thorse preview

thorse

GitHubpushpenderindia/thorse

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

anti-botcommand-and-controlexploit-frameworks+6
6142 years ago
NXcrypt preview

NXcrypt

GitHubhadi999/nxcrypt

NXcrypt - 'python backdoor' framework

encryption-decryption-toolsexploit-frameworkspayload-generation
3679 years ago
siemframework preview

siemframework

GitHubelevenpaths/siemframework

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

exploit-frameworksinformation-gatheringnetwork-mapping+7
426 years ago
TheFatRat preview

TheFatRat

GitHubscreetsec/thefatrat

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

educationexploit-frameworksmalware-analysis+4
11.5k4 years ago
BadAssMacros preview

BadAssMacros

GitHubinf0secrabbit/badassmacros

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

exploit-frameworkspayload-generationred-teaming+1
4455 years ago
SploitScan preview

SploitScan

GitHubxaitax/sploitscan

Aggregates CVE details, exploit databases, and EPSS scores with AI risk assessment and vulnerability scanner import for prioritized patching.

exploit-frameworksosintpenetration-testing+2
1.4k15 days ago
WdToggle preview

WdToggle

GitHuboutflanknl/wdtoggle

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.

exploit-frameworkspost-exploitationred-teaming
2183 years ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
38.9k2 days ago
bad-dicom preview

bad-dicom

GitHubkosmokato/bad-dicom

Explotation framework for CVE-2019-11687

binary-exploitationembedded-systems-securityexploitation+3
61 year ago
libenom preview

libenom

GitHubbounteous17/libenom

CLI wrapper for MSFvenom that streamlines payload creation with profile management, automated listener generation, and organized output for…

exploit-frameworkspayload-developmentpayload-generation+1
2110 years ago
fawkes preview

fawkes

GitHubgaloryber/fawkes

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

cloud-securitycommand-and-controlcontainer-escape+7
361 month ago
Previous12…8Next