Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
inspector preview

inspector

GitHubmodelcontextprotocol/inspector

Inspect, debug, and visually test Model Context Protocol (MCP) servers from a web UI, CLI, or TUI, with tool/resource exploration, request logging,…

ai-securityauthenticationdebuggers+2
10.8k
1 day ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k1 month ago
aggressor_snippets preview

aggressor_snippets

GitHuboctoberfest7/aggressor_snippets

A collection of random small Aggressor snippets that don't warrant their own repo

command-and-controlpenetration-testingred-teaming+1
263 years ago
badger-builder preview

badger-builder

GitHubtw1sm/badger-builder

badger-builder is an AI-assisted tool for generating dynamic Brute Ratel C4 profiles

command-and-controlpayload-developmentred-teaming+1
551 year ago
HttpStrike preview

HttpStrike

GitHubk3ystr0k3r/httpstrike

DDoS script meant to flood websites.

network-securitypenetration-testingred-teaming+2
53 years ago
mofos preview

mofos

GitHubsynacktiv/mofos

Virtual machines manipulation framework

network-securitypenetration-testingred-teaming+3
1085 months ago
SteppingStones preview

SteppingStones

GitHubnccgroup/steppingstones

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

command-and-controlinformation-gatheringpenetration-testing+3
2431 day ago
TS_LLMLib preview

TS_LLMLib

GitHubtrustedsec/ts_llmlib

Python library for local LLM-powered security analysis with Ghidra binary analysis, C/C++ vulnerability scanning, and MCP tool integration for…

ai-securitybinary-analysiscode-analysis+7
13 months ago
PowerExfil preview

PowerExfil

GitHub1n3/powerexfil

A collection of data exfiltration scripts for Red Team assessments.

data-exfiltrationdns-analysiseducation+3
966 years ago
PT-ToolKit preview

PT-ToolKit

GitHubblacksnufkin/pt-toolkit

Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement

exploitationpayload-developmentpenetration-testing+5
724 years ago
Anti_Killer preview

Anti_Killer

GitHubd4vinci/anti_killer

Kill Any Antivirus Using Python For Windows Users .

defensive-toolspenetration-testingred-teaming+1
4510 years ago
rt_redirectors preview

rt_redirectors

GitHubtevora-threat/rt_redirectors

Ansible role to configure redirectors for red team C2

cloud-infrastructure-securitycommand-and-controldevsecops+3
317 years ago
AggressorAssessor preview

AggressorAssessor

GitHubredsiege/aggressorassessor

Aggressor scripts for phases of a pen test or red team assessment

information-gatheringpenetration-testingreconnaissance+3
1832 years ago
log4j-cve-2021-44228 preview

log4j-cve-2021-44228

GitHublucab85/log4j-cve-2021-44228

Ansible playbook automating Red Hat's Log4j detector script to scan Linux hosts for CVE-2021-44228 (Log4Shell) vulnerability with GPG verification.

cloud-securityconfiguration-auditingdevsecops+3
574 years ago
patch-openssl-CVE-2014-0291_CVE-2015-0204 preview

patch-openssl-CVE-2014-0291_CVE-2015-0204

GitHubniccox/patch-openssl-cve-2014-0291_cve-2015-0204

Ansible playbook to patch OpenSSL against CVE-2014-0291 and CVE-2015-0204 on Red Hat family servers, with automated service restart and verification.

cloud-securityconfiguration-auditingdevsecops+2
111 years ago
Ledger preview

Ledger

GitHubshellkraft/ledger

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

command-and-controlincident-responselog-analysis+5
273 months ago
exocomp preview

exocomp

GitHubcookiengineer/exocomp

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

ai-securitycode-analysiseducation+8
160 days ago
third-thoughts preview

third-thoughts

GitHublightless-labs/third-thoughts

Research toolkit for analyzing AI agent behavioral patterns through multi-disciplinary corpus analysis. Parses session logs, runs 23 analytical…

ai-securityanomaly-detectioncurated-resources+5
33 months ago
Previous1234Next