Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
capsulecorp-pentest preview

capsulecorp-pentest

GitHubr3dy/capsulecorp-pentest

Vagrant VirtualBox environment for conducting an internal network penetration test

educationexploit-frameworkslabs-practice+4
1.0k
3 years ago
pystinger preview

pystinger

GitHubfunnywolf/pystinger

Bypass firewall for traffic forwarding using webshell

command-and-controlexploit-frameworksids-ips-evasion+5
1.4k4 years ago
puncia preview

puncia

GitHubarpsyndicate/puncia

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

exploit-frameworksinformation-gatheringosint+6
66522 days ago
flounder preview

flounder

GitHubadshao/flounder

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

ai-securitycode-analysisdynamic-analysis-sandboxing+5
5148 days ago
ronin preview

ronin

GitHubronin-rb/ronin

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

cryptographyctfdns-analysis+9
7598 months ago
Nebula preview

Nebula

GitHubgl4ssesbo1/nebula

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

cloud-securitycommand-and-controlexploit-frameworks+3
6351 year ago
KittyStager preview

KittyStager

GitHubenelg52/kittystager

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

command-and-controleducationencryption-decryption-tools+6
2263 years ago
autopentest-ai preview

autopentest-ai

GitHubbhavsec/autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

crawlereducationexploit-frameworks+8
2307 months ago
wasmforge preview

wasmforge

GitHubpraetorian-inc/wasmforge

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

binary-analysiscommand-and-controlexploit-frameworks+9
1313 months ago
SindriKit preview

SindriKit

GitHubyoussefnoob003/sindrikit

A foundational C library for building operationally credible offensive capabilities

binary-exploitationcode-analysiseducation+6
914 days ago
csaf preview

csaf

GitHubcsalab-id/csaf

Cyber Security Awareness Framework (CSAF)

ctfdefensive-toolseducation+9
1057 months ago
stratum-c2 preview

stratum-c2

GitHublame-projects/stratum-c2

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

cloud-securitycommand-and-controlencryption-decryption-tools+6
4215 days ago
AttackSurfaceManagement preview

AttackSurfaceManagement

GitHub1n3/attacksurfacemanagement

Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam…

exploit-frameworksinformation-gatheringosint+6
1064 years ago
reave preview

reave

GitHubpsmths/reave

WIP Post-exploitation framework tailored for hypervisors.

command-and-controldata-exfiltrationexploit-frameworks+8
513 years ago
CVE-2026-54121-PoC-Exploit preview

CVE-2026-54121-PoC-Exploit

GitHubtc4dy/cve-2026-54121-poc-exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

authentication-authorizationexploitationexploit-frameworks+5
2913 days ago
hazel-cve-2026-43499 preview

hazel-cve-2026-43499

GitHubdorlow/hazel-cve-2026-43499

Firmware-specific temporary root exploit for Toshiba/Amazon Fire TV (hazel) using CVE-2026-43499. Implements ARM32 futex-PI UAF, kernel address leak,…

android-securitybinary-exploitationembedded-systems-security+6
18 days ago
metasploit-bailiwicked_domain-fix preview

metasploit-bailiwicked_domain-fix

GitHubhamlasiraj/metasploit-bailiwicked_domain-fix

Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)

dns-analysiseducationexploitation+3
11 year ago
Oihk-pentesting preview

Oihk-pentesting

GitHubbroskigx/oihk-pentesting

Autonomous multi-agent AI penetration-testing engine: a governed tool sandbox, an immutable evidence-and-validation gate, and a reproducible…

ai-securityeducationexploit-frameworks+7
44 days ago
Previous12Next