Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
Dark-Moon preview

Dark-Moon

GitHubascit31/dark-moon

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

ai-securitycloud-securitydevsecops+6
875
5 days ago
CVE-2026-54121-PoC-Exploit preview

CVE-2026-54121-PoC-Exploit

GitHubtc4dy/cve-2026-54121-poc-exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

authentication-authorizationexploitationexploit-frameworks+5
271 month ago
DoHC2 preview
Archived

DoHC2

GitHubspiderlabs/dohc2

DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS…

command-and-controldns-analysisexploit-frameworks+3
4496 years ago
msfrpc preview
Archived

msfrpc

GitHubspiderlabs/msfrpc

Perl/Python modules for interfacing with Metasploit MSGRPC

command-and-controlexploit-frameworkspayload-development+3
976 years ago
Decepticon preview

Decepticon

GitHubpurpleailab/decepticon

Autonomous Hacking Agent for Red Team

ai-securitycommand-and-controlctf+9
5.3k4 days ago
NetExec preview

NetExec

GitHubpennyw0rth/netexec

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

command-and-controldatabase-securityexploitation+14
5.8k19h 52m ago
guardian-cli preview

guardian-cli

GitHubzakirkun/guardian-cli

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

ai-securitycloud-securityeducation+8
1.9k2 months ago
pentest-ai-agents preview

pentest-ai-agents

GitHub0xsteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

ai-securitycloud-securityeducation+8
2.2k14 days ago
WinPwn preview

WinPwn

GitHubs3cur3th1ssh1t/winpwn

Automation for internal Windows Penetrationtest / AD-Security

exploitationpenetration-testingpenetration-testing-frameworks+4
3.7k1 year ago
Ninja preview

Ninja

GitHubahmedkhlief/ninja

Open source C2 server created for stealth red team operations

command-and-controlexploitationinformation-gathering+6
8403 years ago
Nuages preview

Nuages

GitHubp3nt4/nuages

A modular C2 framework

command-and-controlexploit-frameworkslateral-movement+5
5462 months ago
capsulecorp-pentest preview

capsulecorp-pentest

GitHubr3dy/capsulecorp-pentest

Vagrant VirtualBox environment for conducting an internal network penetration test

educationexploit-frameworkslabs-practice+4
1.0k3 years ago
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
5149 days ago
APEX preview

APEX

GitHubluemmelsec/apex

Azure Post Exploitation Framework

cloud-securitydata-exfiltrationexploit-frameworks+4
24810 months ago
SynthAPT preview

SynthAPT

GitHubacedef/synthapt

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

adversarial-attackai-securitycommand-and-control+8
2354 months ago
FruityC2 preview

FruityC2

GitHubxtr4nge/fruityc2

FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed from a web…

command-and-controlexploit-frameworkspayload-development+4
2068 years ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
8310 days ago
whiskeysamlandfriends preview

whiskeysamlandfriends

GitHubsecureworks/whiskeysamlandfriends

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

authentication-authorizationcloud-securityexploit-frameworks+3
812 years ago
Previous12Next