Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
TransparentTorProxy preview

TransparentTorProxy

GitHubonyks-os/transparenttorproxy

A Linux CLI utility that transparently routes all system traffic through the Tor network using nftables. It enables rapid IP rotation and easy…

command-and-controldefensive-toolsdns-analysis+6
44
2 days ago
overload preview
Archived

overload

GitHubgoncalopolido/overload

A network stress testing tool for simulating high traffic loads.

network-securitypenetration-testingred-teaming+2
4333 months ago
adaptix-serverless-c2 preview

adaptix-serverless-c2

GitHubstillbigjosh/adaptix-serverless-c2

Serverless C2 transport plugin for AdaptixC2 v1.2 using AWS Lambda + DynamoDB as the relay infrastructure.

cloud-infrastructure-securitycloud-securitycommand-and-control+8
198 days ago
rt_redirectors preview

rt_redirectors

GitHubtevora-threat/rt_redirectors

Ansible role to configure redirectors for red team C2

cloud-infrastructure-securitycommand-and-controldevsecops+3
317 years ago
Cuteit preview

Cuteit

GitHubd4vinci/cuteit

IP obfuscator made to make a malicious ip a bit cuter

command-and-controlids-ips-evasionpayload-generation+4
5461 year ago
Invoke-SelfSignedWebRequest preview

Invoke-SelfSignedWebRequest

GitHub0sm0s1z/invoke-selfsignedwebrequest

This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and press on with…

command-and-controlids-ips-evasionpenetration-testing+4
129 years ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
12.0k3 days ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k1 month ago
pentest-copilot preview

pentest-copilot

GitHubbugbasesecurity/pentest-copilot

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

ai-securitycommand-and-controlctf+8
1.5k1 month ago
pwncat preview

pwncat

GitHubcytopia/pwncat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

command-and-controlids-ips-evasionlateral-movement+7
2.0k4 years ago
pentest-harness preview

pentest-harness

GitHubs1n6h/pentest-harness

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

ai-securitycommand-and-controlctf+7
40727 days ago
SteppingStones preview

SteppingStones

GitHubnccgroup/steppingstones

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

command-and-controlinformation-gatheringpenetration-testing+3
2432 days ago
evil-winrm-py preview

evil-winrm-py

GitHubadityatelange/evil-winrm-py

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

authenticationcommand-and-controllateral-movement+7
40618 days ago
ezsploit preview

ezsploit

GitHubrand0m1ze/ezsploit

Linux bash script automation for metasploit

command-and-controlexploit-frameworkspayload-development+5
26910 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5444 years ago
paragon preview

paragon

GitHubkcarretto/paragon

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

command-and-controlexploit-frameworkspayload-development+4
3062 years ago
Converto preview

Converto

GitHubdeveloperkunal/converto

Installing Kali linux on Vps Server

penetration-testingred-teamingremote-access-tool+1
1167 years ago
python-pentesting preview

python-pentesting

GitHubustayready/python-pentesting

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

cloud-securitycommand-and-controleducation+6
2196 years ago
Previous123Next