Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
BypassAV preview

BypassAV

GitHubmatro7sh/bypassav

This map lists the essential techniques to bypass anti-virus and EDR

curated-resourceseducationids-ips-evasion+2
3.4k1 year ago
demiguise preview

demiguise

GitHubnccgroup/demiguise

HTA encryption tool for RedTeams

ids-ips-evasionpayload-generationphishing-tools+2
1.4k4 years ago
GhostESP preview

GhostESP

GitHubghostesp-revival/ghostesp

The open-source wireless research platform for ESP32.

bluetooth-securityembedded-systems-securityhardware-hacking+8
8942 days ago
SniffAir preview

SniffAir

GitHubtylous/sniffair

A framework for wireless pentesting.

exploitationinformation-gatheringpenetration-testing+3
1.2k5 years ago
xalgorix preview

xalgorix

GitHubxalgord/xalgorix

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

ai-securitydevsecopsdynamic-analysis-sandboxing+7
8711 day ago
Phishious preview

Phishious

GitHubcaniphish/phishious

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

email-securityinformation-gatheringmisconfiguration+3
5183 years ago
RedTeam_toolkit preview

RedTeam_toolkit

GitHubsignorrayan/redteam_toolkit

Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.

exploitationinformation-gatheringpassword-attacks+5
5726 months ago
chain-reactor preview

chain-reactor

GitHubredcanaryco/chain-reactor

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

adversarial-attackdefensive-toolseducation+2
3451 year ago
NorthStarC2 preview

NorthStarC2

GitHubeng1ndes/northstarc2

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

command-and-controldata-exfiltrationinformation-gathering+6
2692 years ago
MAAD-AF preview

MAAD-AF

GitHubvectra-ai-research/maad-af

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

adversarial-attackcloud-securitydata-exfiltration+6
4317 months ago
Invoke-ArgFuscator preview

Invoke-ArgFuscator

GitHubwietze/invoke-argfuscator

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…

curated-resourcesids-ips-evasionpayload-generation+2
2806 months ago
secret_handshake preview

secret_handshake

GitHubjconwell/secret_handshake

A prototype malware C2 channel using x509 certificates over mTLS

command-and-controldata-exfiltrationids-ips-evasion+1
1532 years ago
silph preview

silph

GitHubalmounah/silph

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

authenticationmemory-forensicspassword-cracking+3
1388 months ago
Fenrir preview

Fenrir

GitHubnccgroup/fenrir

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

command-and-controllateral-movementpenetration-testing+3
6711 years ago
loki preview

loki

GitHubnccgroup/loki

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

data-exfiltrationlateral-movementpenetration-testing+3
6310 years ago
trappsec preview

trappsec

GitHubtrappsec-dev/trappsec

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

api-securitydefensive-toolsidentity-access-management+5
122 months ago
CVE-2025-68613-POC preview

CVE-2025-68613-POC

GitHubthestingr/cve-2025-68613-poc

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

educationexploitationinformation-gathering+8
287 months ago
mcp-pwn preview

mcp-pwn

GitHubjf-gondim/mcp-pwn

PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling…

command-and-controleducationexploitation+4
2 months ago
Previous123Next