Cyber Security News

KittySploit – AI-Powered Next-Generation Penetration Testing Framework With 1150+ Modules

KittySploit is a new open-source penetration testing framework that combines a Python and Zig codebase with autonomous AI agents, ship­ping with over 1,150 modules for offensive security teams.

The tool chain includes reconnaissance, exploitation, traffic analysis, payload generation, collaboration, and post-exploitation workflows.

Kitty Interface

KittySploit’s core difference is its integration of local large language models via Ollama, which allows AI agents to autonomously plan attack paths after being fed just a target name.

This autonomous agent handles reconnaissance and suggests exploitation strategies without constant manual input, a capability that aligns with the broader industry shift toward AI-driven pentesting agents seen in tools like PentAGI and xOffense.

KittySploit Penetration Testing Tool

The framework’s headline capability is its autonomous agent. Operators can provide a target and connect KittySploit to a locally hosted large language model through Ollama.

The agent is intended to organize reconnaissance findings, evaluate available modules, and propose possible attack paths without sending sensitive engagement data to a hosted AI service.

Kitty OSINT

Recent code changes show a default local Ollama endpoint and add planning, response caching, workflow, and HTTP-intelligence components, indicating that the AI layer extends beyond a simple chatbot interface.

The framework’s payloads are compiled using an integrated Zig 0.16 toolchain, producing stealthy, dependency-free x64 polymorphic encoders designed to bypass modern EDR and WAF defenses.

This evasion-first approach, combined with multi-protocol session handling and native Tor routing, positions KittySploit against automated defense systems that have made traditional exploitation frameworks less effective.

Compared to legacy tools written in Ruby or Java, this modern Python/Zig hybrid core is built for speed and stealth in contemporary web environments.

A standout feature is KittyProxy, an intelligent web proxy that auto-discovers REST APIs, GraphQL endpoints, and WebSocket connections, then automatically runs relevant exploitation modules directly from observed traffic.

This “smart proxy” capability removes manual mapping steps that typically slow down assessments of modern web architectures, addressing a gap that many legacy scanners still struggle to close.

KittySploit ships with KittyCollab, a real-time shared editor for team-based operations, alongside a modern web UI for both proxy analysis and collaborative workflows.

The framework also includes a community-driven marketplace where users can install or share new modules, an ecosystem feature notably not available in Metasploit and Cobalt Strike.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago