Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k3 months ago
AllHackingTools preview

AllHackingTools

GitHubmishakorzik/allhackingtools

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

crawlerexploitationhash-analysis+8
6.2k7 days ago
nccfsas preview

nccfsas

GitHubnccgroup/nccfsas

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

command-and-controlexploitationinformation-gathering+8
6094 years ago
killchain preview

killchain

GitHubruped24/killchain

A unified console to perform the "kill chain" stages of attacks.

command-and-controlexploit-frameworkspayload-generation+5
2083 years ago
tap preview

tap

GitHubtrustedsec/tap

The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.

command-and-controlpenetration-testing-frameworkspersistence-mechanisms+3
5053 years ago
ghostlock-vagrant-box preview

ghostlock-vagrant-box

GitHubdaniyal48/ghostlock-vagrant-box

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed…

ctfeducationexploitation+3
12 months ago
hcxtools preview

hcxtools

GitHubzerbea/hcxtools

A small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper.

hash-analysispassword-crackingpenetration-testing-frameworks+2
2.5k0 days ago
stride-gpt preview

stride-gpt

GitHubmrwadams/stride-gpt

An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE…

ai-securityeducationpenetration-testing-frameworks+2
1.1k2 days ago
Redeye preview

Redeye

GitHubredeye-framework/redeye

Collaborative pentest data management platform for organizing servers, users, vulnerabilities, attack vectors, and files with API access and graph…

information-gatheringpenetration-testingpenetration-testing-frameworks+2
4723 years ago
threatbox preview

threatbox

GitHubthreatexpress/threatbox

Ansible-based attack platform for deploying and managing a standardized Linux penetration testing environment with automated tool installation,…

penetration-testing-frameworksred-teamingscripting-automation+1
771 year ago
Viper preview

Viper

GitHubfunnywolf/viper

Adversary simulation and Red teaming platform with AI

adversarial-attackai-securitycommand-and-control+5
5.3k3 months ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2345 months ago
redthread preview

redthread

GitHubmatheusht/redthread

An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision…

adversarial-attackai-securitydefensive-tools+7
505 days ago
PyRIT preview
Archived

PyRIT

GitHubazure/pyrit

The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to…

adversarial-attackai-securityeducation+2
1146 months ago
caldera preview

caldera

GitHubapache/caldera

Automated Adversary Emulation Platform

adversarial-attackcommand-and-controlctf+7
7.3k29 days ago
deep-pwning preview

deep-pwning

GitHubcchio/deep-pwning

Metasploit for machine learning.

adversarial-attackai-securityexploit-frameworks+2
5694 years ago
Atomic-Red-Team-C2 preview

Atomic-Red-Team-C2

GitHubdarmado/atomic-red-team-c2

ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via…

command-and-controlexploit-frameworkspayload-generation+3
1782 years ago
Covenant preview

Covenant

GitHubcobbr/covenant

Covenant is a collaborative .NET C2 framework for red teamers.

command-and-controlexploit-frameworkspayload-generation+2
4.7k5 years ago
Previous123Next