Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
136 results
clusterd preview

clusterd

GitHubhatriot/clusterd

application server attack toolkit

exploit-frameworkspayload-generationpenetration-testing+3
68710 years ago
Phishious preview

Phishious

GitHubcaniphish/phishious

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

email-securityinformation-gatheringmisconfiguration+3
5183 years ago
Pompem preview

Pompem

GitHubrfunix/pompem

Find exploit tool

exploit-frameworksinformation-gatheringpenetration-testing+1
1.0k7 years ago
RedTeam_toolkit preview

RedTeam_toolkit

GitHubsignorrayan/redteam_toolkit

Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.

exploitationinformation-gatheringpassword-attacks+5
5726 months ago
BlueHound preview

BlueHound

GitHubzeronetworks/bluehound

BlueHound - pinpoint the security issues that actually matter

defensive-toolseducationinformation-gathering+4
7713 years ago
chain-reactor preview

chain-reactor

GitHubredcanaryco/chain-reactor

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

adversarial-attackdefensive-toolseducation+2
3451 year ago
NorthStarC2 preview

NorthStarC2

GitHubeng1ndes/northstarc2

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

command-and-controldata-exfiltrationinformation-gathering+6
2692 years ago
MAAD-AF preview

MAAD-AF

GitHubvectra-ai-research/maad-af

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

adversarial-attackcloud-securitydata-exfiltration+6
4317 months ago
tulpar preview

tulpar

GitHubtulpar/tulpar

Tulpar - Web Vulnerability Scanner

information-gatheringosintpenetration-testing+3
2018 years ago
Invoke-ArgFuscator preview

Invoke-ArgFuscator

GitHubwietze/invoke-argfuscator

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…

curated-resourcesids-ips-evasionpayload-generation+2
2806 months ago
CVE-2023-25157 preview

CVE-2023-25157

GitHubwin3zz/cve-2023-25157

CVE-2023-25157 - GeoServer SQL Injection - PoC

exploitationinformation-gatheringpenetration-testing+2
1673 years ago
wanderer preview

wanderer

GitHubgh0x0st/wanderer

An open-source process injection enumeration tool written in C#

information-gatheringpenetration-testing
1743 years ago
Carnivore preview

Carnivore

GitHubnccgroup/carnivore

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

authenticationinformation-gatheringpenetration-testing+1
1485 years ago
Metadata-Attacker preview

Metadata-Attacker

GitHubrub-nds/metadata-attacker

A tool to generate media files with malicious metadata

information-gatheringpayload-generationpenetration-testing+1
1287 years ago
DracOS preview

DracOS

GitHubscreetsec/dracos

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

educationexploitationforensics+8
589 years ago
WebFEET preview

WebFEET

GitHubnccgroup/webfeet

Web Filter External Enumeration Tool (WebFEET)

information-gatheringpenetration-testingreconnaissance+2
7812 years ago
silph preview

silph

GitHubalmounah/silph

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

authenticationmemory-forensicspassword-cracking+3
1388 months ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1197 months ago
Previous1…345…8Next