KittySploit Framework
Modular offensive security console: modules, C2, marketplace installs and local execution. You keep the toolchain.
- Complete open-source framework
- Local and self-hosted operation
- 619 stars · 99 forks
CATALOG FREE AND PAID
Open-source tools you run yourself. Optional KittySploit Reports when the deliverable has to leave the lab. Every card says whether it is free or paid.
The two layers most people start with: execute locally, then publish if you need a client report.
Modular offensive security console: modules, C2, marketplace installs and local execution. You keep the toolchain.
Turn findings into a client-ready report. Editors are billed; viewers stay free. Encryption happens in the browser.
The catalog of extensions you install into your own Framework. First-party tools below are free; the public catalog also lists paid packages.
Browse modules, plugins, interfaces and middleware. Install with market install. Paid items check out once; they still run on your machine.
HTTP/HTTPS intercepting proxy with API, GraphQL and WebSocket discovery from live traffic.
View on GitHub ↗Modern web GUI for campaigns, proxy analysis and day-to-day operator workflows.
View on GitHub ↗Turn scattered OSINT signals into a connected graph — domains, emails, infra and relationships.
View on GitHub ↗PCAP protocol analysis and investigation UI for traffic that lives outside the browser.
View on GitHub ↗V8/Frida memory workbench with Chrome DevTools Protocol support for browser and runtime work.
View on GitHub ↗Real-time shared editor for scripts, notes and payloads — same session, same context, same target.
View on GitHub ↗Control hub for authorized nodes — topology map, health checks, and remote CLI dispatch across labs and field ops.
View on GitHub ↗Chat-style pentest workspace — plan first, then confirm module and command runs, with skills and durable memory.
View on GitHub ↗Public catalog, docs and the read-only Modules API. All free to use.
Read-only Search API for the live module index. Filter by type, CVE, author and date. No auth required.
Open API docs →Browse modules, CVEs and packages in the public catalog used by the Framework marketplace.
Open search.kittysploit.com ↗Install, usage, marketplace publishing and operator guides for the Framework and extensions.
Open docs ↗Need something that is not listed? Community packages live in the Marketplace. Partnerships are separate from product pricing.
START WHERE YOU NEED KEEP THE REST OPTIONAL
Install the Framework, browse extensions, or try Reports on a sample workspace. Each product stays independent.