Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
153 results
Medusa preview

Medusa

GitHubascotbe/medusa

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

dns-analysisexploit-frameworkspayload-generation+4
2.2k
3 years ago
GyoiThon preview

GyoiThon

GitHubgyoisamurai/gyoithon

GyoiThon is a growing penetration test tool using Machine Learning.

exploit-frameworksinformation-gatheringmachine-learning+5
8285 years ago
CapTipper preview

CapTipper

GitHubomriher/captipper

Malicious HTTP traffic explorer

digital-forensicsexploit-frameworksforensics+5
7265 years ago
rekono preview

rekono

GitHubpablosnt/rekono

Offensive security platform that automates attack surface discovery and vulnerability management

exploit-frameworksosintpenetration-testing+4
60725 days ago
burp-vulners-scanner preview

burp-vulners-scanner

GitHubvulnerscom/burp-vulners-scanner

Vulnerability scanner based on vulners.com search API

exploit-frameworksvulnerability-analysisvulnerability-scanners+1
89911 months ago
POC-S preview

POC-S

GitHubjiangsir404/poc-s

POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC

dns-analysisexploit-frameworksfuzzing+5
3556 years ago
msploitego preview

msploitego

GitHubshizzz477/msploitego

Pentesting suite for Maltego based on data in a Metasploit database

exploit-frameworksinformation-gatheringnetwork-mapping+6
1488 years ago
webdiscover preview

webdiscover

GitHubv1n1v131r4/webdiscover

The purpose of this script is to automate the web enumeration process and search for exploits

exploit-frameworksreconnaissancevulnerability-scanners+1
1174 years ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12613 years ago
meteor preview

meteor

GitHubdegenerat3/meteor

A cross-platform C2/teamserver supporting multiple transport protocols, written in Go.

command-and-controlexploit-frameworksnetwork-security+4
453 years ago
BurpSuite-Plugin preview

BurpSuite-Plugin

GitHubjas502n/burpsuite-plugin

Plugin For BurpSuite (Pentester)

penetration-testing-frameworksvulnerability-analysisweb-application-exploitation+2
375 years ago
PAKURI-THON preview

PAKURI-THON

GitHub01rabbit/pakuri-thon

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

command-and-controlexploit-frameworksinformation-gathering+7
284 years ago
faraday_templates preview

faraday_templates

GitHubinfobyte/faraday_templates

Template repository for Faraday security platform, providing reusable vulnerability scanning and exploitation templates for automated penetration…

exploit-frameworksnetwork-securitypenetration-testing-frameworks+2
66 years ago
wp2shell-checker preview

wp2shell-checker

GitHub0xjessie21/wp2shell-checker

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

exploitationnetwork-securitypenetration-testing-frameworks+2
11 month ago
CVE-2020-0796 preview

CVE-2020-0796

GitHubjulixsalas/cve-2020-0796

Metasploit Auxiliary module for scanning and detecting CVE-2020-0796 (SMBGhost) vulnerability in Windows SMBv3 implementations.

exploitationexploit-frameworksnetwork-security+3
14 years ago
MagicArch preview

MagicArch

GitLabmagicbytes/magicarch

MagicArch is a comprehensive post-installation script built with Ansible, designed to transform a basic Arch Linux installation into a fully equipped…

exploit-frameworksforensicsinformation-gathering+8
22 years ago
purpleteam-orchestrator preview
Archived

purpleteam-orchestrator

GitLabpurpleteam-labs/purpleteam-orchestrator

Orchestration component of purpleteam

cloud-securitydevsecopspenetration-testing-frameworks+2
15 years ago
vulnreport preview
Archived

vulnreport

GitHubsalesforce/vulnreport

Open-source pentesting management and automation platform by Salesforce Product Security

devsecopspenetration-testingpenetration-testing-frameworks+2
6004 years ago
Previous123…9Next