Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
339 results
Jasmin-Ransomware preview

Jasmin-Ransomware

GitHubcodesiddhant/jasmin-ransomware

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

command-and-controlencryption-decryption-toolsexploitation+5
287
5 years ago
Project-Onyx preview

Project-Onyx

GitHubx-3306/project-onyx

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

ai-securitycommand-and-controlcryptography+6
11810 days ago
GoRedOps preview
Archived

GoRedOps

GitHubkiexitdispatcher/goredops

🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on…

anti-botbinary-analysiscommand-and-control+9
6701 year ago
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
21 month ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubhualy13/cve-2025-55182

Automated proof-of-concept exploit for Next.js RCE (CVE-2025-55182) with interactive shell, batch scanning, and advanced payload encoding for…

exploitationpayload-developmentpenetration-testing+3
49 months ago
CVE-2024-27348-HugeGraph-RCE preview

CVE-2024-27348-HugeGraph-RCE

GitHubakelaqe/cve-2024-27348-hugegraph-rce

Advanced PoC exploit for CVE-2024-27348, achieving reliable RCE in Apache HugeGraph via sandbox bypass and non-blind command execution.

exploitationpayload-developmentpenetration-testing+3
16 months ago
LlamaStack-RCE-Deterministic-Supply-Chain-Exploitation-Hardening-Framework-CVE-2024-50050- preview

LlamaStack-RCE-Deterministic-Supply-Chain-Exploitation-Hardening-Framework-CVE-2024-50050-

GitHubsastraadiwiguna-purpleeliteteaming/llamastack-rce-deterministic-supply-chain-exploitation-hardening-framework-cve-2024-50050-

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

ai-securitybinary-exploitationcommand-and-control+9
8 months ago
Next.js-RCE-Scanner---CVE-2025-55182-CVE-2025-66478 preview

Next.js-RCE-Scanner---CVE-2025-55182-CVE-2025-66478

GitHubmustafa1p/next.js-rce-scanner---cve-2025-55182-cve-2025-66478

An advanced vulnerability scanner for detecting **CVE-2025-55182** and **CVE-2025-66478** - critical Remote Code Execution (RCE) vulnerabilities in…

exploitationpayload-developmentpenetration-testing+3
9 months ago
Koppeling preview

Koppeling

GitHubmonoxgas/koppeling

Adaptive DLL hijacking / dynamic export forwarding

binary-exploitationexploitationpayload-development+1
8206 years ago
Claude-Red preview

Claude-Red

GitHubsnailsploit/claude-red

Curated library of 78 offensive security SKILL.md modules that prime Claude with expert red team methodology across web, AD, wireless, cloud, and…

ai-securitycurated-resourceseducation+8
6.8k7 days ago
redamon preview

redamon

GitHubsamugit83/redamon

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

ai-securityexploit-frameworkslateral-movement+8
2.6k2 days ago
Viper preview

Viper

GitHubfunnywolf/viper

Adversary simulation and Red teaming platform with AI

adversarial-attackai-securitycommand-and-control+5
5.3k3 months ago
LitterBox preview

LitterBox

GitHubblacksnufkin/litterbox

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end…

ai-securitydynamic-analysis-sandboxingmalware-analysis+4
1.5k4 months ago
UnhookMe preview

UnhookMe

GitHubmgeeky/unhookme

Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

defensive-toolspayload-developmentred-teaming
3474 years ago
Red-Teaming-Toolkit preview

Red-Teaming-Toolkit

GitHubinfosecn1nja/red-teaming-toolkit

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

command-and-controlcurated-resourceslateral-movement+6
10.7k4 months ago
RedTeam-Tools preview

RedTeam-Tools

GitHuba-poc/redteam-tools

Tools and Techniques for Red Team / Penetration Testing

exploitationlateral-movementosint+7
9.8k5 months ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k19 days ago
Mythic preview

Mythic

GitHubits-a-feature/mythic

A collaborative, multi-platform, red teaming framework

command-and-controldata-exfiltrationexploitation+9
4.8k19 days ago
Previous12…19Next