Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
401 results
gallia preview

gallia

GitHubfraunhofer-aisec/gallia

Extendable pentesting framework for automotive UDS interfaces, enabling reproducible scans, diagnostic trouble code reading, and post-processing via…

fuzzingpenetration-testing-frameworks
1620 days ago
theo preview

theo

GitHubcleanunicorn/theo

Ethereum recon and exploitation tool.

exploit-frameworkspenetration-testing-frameworksreconnaissance+1
3491 year ago
frieren preview

frieren

GitHubxchwarze/frieren

Frieren is a micro-framework designed for use in routers and Single Board Computers (SBCs). This framework is built to be lightweight, efficient, and…

embedded-systems-securityhardware-iot-securityiot-security+8
22519 days ago
FruityC2 preview

FruityC2

GitHubxtr4nge/fruityc2

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

command-and-controlexploit-frameworkspayload-development+4
2068 years ago
EaST preview

EaST

GitHubc0rel0ader/east

Exploits and Security Tools Framework 2.0.1

binary-exploitationeducationexploitation+4
3074 years ago
zuthaka preview

zuthaka

GitHubpucarasec/zuthaka

Open-source C2 integration framework providing a unified web interface for managing multiple command-and-control instances, listeners, agents, and…

command-and-controlexploit-frameworkspenetration-testing-frameworks+2
1813 years ago
BokuLoader preview

BokuLoader

GitHubxforcered/bokuloader

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

adversarial-attackcommand-and-controlids-ips-evasion+4
3322 years ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
1453 days ago
Elite preview

Elite

GitHubcobbr/elite

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

command-and-controldynamic-code-analysisencryption-decryption-tools+6
1217 years ago
pyCobaltHound preview

pyCobaltHound

GitHubnvisosecurity/pycobalthound

pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Bloodhound.

exploit-frameworksinformation-gatheringlateral-movement+5
1354 years ago
specula preview

specula

GitHubtrustedsec/specula

Modular command-and-control framework abusing Microsoft Outlook's Home Page feature for stealthy persistence, remote access, and post-exploitation.

command-and-controlpenetration-testing-frameworkspersistence-mechanisms+2
2371 year ago
pown preview

pown

GitHubpownjs/pown

Pown.js is a security testing an exploitation toolkit built on top of Node.js and NPM.

exploit-frameworkspenetration-testing-frameworksscripting-automation+1
2603 years ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2355 months ago
ROP_ROCKET preview

ROP_ROCKET

GitHubbw3ll/rop_rocket

ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Syscalls attack,…

binary-exploitationexploitationexploit-frameworks+4
18210 months ago
Atomic-Red-Team-C2 preview

Atomic-Red-Team-C2

GitHubdarmado/atomic-red-team-c2

ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via…

command-and-controlexploit-frameworkspayload-generation+3
1782 years ago
redStackPRO preview

redStackPRO

GitHubdevzero-security/redstackpro

A canvas for red team infrastructure and cyber ranges. Compose a topology, export runnable Terraform and Ansible, and deploy it yourself. Your cloud…

cloud-infrastructure-securitycloud-securitycommand-and-control+8
1373 days ago
autopentest-ai preview

autopentest-ai

GitHubbhavsec/autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

crawlereducationexploit-frameworks+8
2337 months ago
pentest-mcp preview

pentest-mcp

GitHubdmontgomery40/pentest-mcp

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

exploitationfuzzingnetwork-mapping+8
1476 months ago
Previous1…678…23Next