Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
metarget preview

metarget

GitHubmetarget/metarget

Automated framework for deploying vulnerable cloud-native infrastructures, enabling rapid installation of CVEs in Docker, Kubernetes, and Linux…

cloud-securitycontainer-securityeducation+4
1.4k
1 month ago
metasploitable3 preview

metasploitable3

GitHubrapid7/metasploitable3

Deliberately vulnerable virtual machine designed as a target for practicing exploit development and penetration testing with Metasploit. Includes a…

dynamic-analysis-sandboxingeducationexploit-frameworks+4
5.7k1 year ago
kubesploit preview

kubesploit

GitHubcyberark/kubesploit

Cross-platform HTTP/2 C2 server and agent for post-exploitation in containerized environments, featuring container breakout modules, Kubernetes CVE…

command-and-controlcontainer-escapecontainer-security+8
1.2k1 year ago
exploit-CVE-2017-6090 preview

exploit-CVE-2017-6090

GitHubjlk/exploit-cve-2017-6090

Dockerized vulnerable PhpCollab instance for practicing CVE-2017-6090 remote code execution with Metasploit integration and guided exploitation…

container-securityeducationexploit-frameworks+3
18 years ago
openclarity preview
Archived

openclarity

GitHubopenclarity/openclarity

Agentless platform for discovering and managing VM security threats including vulnerabilities, malware, rootkits, misconfigurations, leaked secrets,…

cloud-infrastructure-securitycloud-securitycontainer-security+7
1.5k3 months ago
pentest-ai-agents preview

pentest-ai-agents

GitHub0xsteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

ai-securitycloud-securityeducation+8
2.2k8 days ago
GEVAUDAN preview

GEVAUDAN

GitHubmauroeldritch/gevaudan

Exploit for Red Hat / GlusterFS CVE-2018-1088 & CVE-2018-1112, featured @ DEFCON 26, Las Vegas!

authenticationcontainer-securityexploitation+3
106 years ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

Exploit and post-exploitation framework for Next.js RSC (CVE-2025-55182), with interactive RCE, file transfer, persistence, enumeration, and privesc.

command-and-controlcontainer-escapedata-exfiltration+7
8 months ago
Dark-Moon preview

Dark-Moon

GitHubascit31/dark-moon

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

ai-securitycloud-securitydevsecops+6
8661 day ago
Metasploit-Module-TFM preview

Metasploit-Module-TFM

GitHubcgv-dev/metasploit-module-tfm

Custom Metasploit module exploiting Kubernetes secret mount policy bypass (CVE-2023-2728, CVE-2024-3177) to retrieve secrets via crafted pods.

cloud-securitycontainer-securityeducation+7
1 year ago
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k5 days ago
CyberStrikeAI preview

CyberStrikeAI

GitHubed1s0nz/cyberstrikeai

AI-native security testing platform integrating 100+ tools with agentic orchestration, role-based testing, MCP-native tools, C2 capabilities, and…

ai-securitybinary-analysiscloud-security+9
5.9k1 day ago
pacu preview

pacu

GitHubrhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

cloud-infrastructure-securitycloud-securitydata-exfiltration+7
5.3k5 months ago
CyberStrike preview

CyberStrike

GitHubcyberstrikeus/cyberstrike

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

ai-securitycloud-securityeducation+9
2.0k1 day ago
PackMyPayload preview

PackMyPayload

GitHubmgeeky/packmypayload

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

container-securityexploit-frameworkspayload-development+3
1.2k2 years ago
Redcloud preview

Redcloud

GitHubkhast3x/redcloud

Automated Red Team Infrastructure deployement using Docker

container-securityexploit-frameworkspenetration-testing-frameworks+1
1.3k4 years ago
SpoolSploit preview

SpoolSploit

GitHubbeetlechunks/spoolsploit

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

container-securityexploitationexploit-frameworks+4
5525 years ago
offensive-docker preview

offensive-docker

GitHubaaaguirrep/offensive-docker

Docker image bundling 200+ offensive security tools for rapid penetration testing, reconnaissance, exploitation, and vulnerability assessment with…

container-securityexploit-frameworkspassword-cracking+5
7694 years ago
Previous12Next