Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Categories

Browse cybersecurity tools by security context and purpose.

Categories

  • Defensive ToolsTools for blue team, defensive security, and threat protection.950 tools
  • ReconnaissanceTools for gathering information about targets and identifying attack surfaces.14783 tools
    • OSINT (Open Source Intelligence)Tools for collecting and analyzing publicly available information from online sources.1219 tools
    • Network MappingTools for discovering network topology, devices, and services.457 tools
    • DNS & Subdomain EnumerationTools for discovering subdomains and DNS records associated with target domains.207 tools
    • Information GatheringGeneral purpose tools for collecting various types of information about targets.5848 tools
  • Password AttacksPassword cracking, brute-force, wordlists, and credential testing tools.841 tools
  • Vulnerability AnalysisTools for identifying, assessing, and prioritizing security weaknesses in systems and applications.29480 tools
    • Vulnerability ScannersAutomated tools for detecting known vulnerabilities in systems and applications.3289 tools
    • Static Code Analysis (SAST)Tools for examining source code without execution to find security flaws.132 tools
    • Dynamic Code Analysis (DAST)Tools for analyzing application behavior during runtime to find security vulnerabilities.84 tools
    • Configuration AuditingTools for reviewing system and application configurations for security weaknesses and compliance.799 tools
  • Code AnalysisStatic and dynamic code analysis, SAST, DAST, and code review tools.1950 tools
  • ExploitationTools for weaponizing vulnerabilities to gain unauthorized access to systems or data.27638 tools
    • Penetration Testing FrameworksIntegrated platforms for developing, executing, and managing penetration tests.362 tools
    • Payload GenerationTools for creating and customizing malicious code or instructions to execute after exploitation.3377 tools
    • ShellcodeTools for crafting and manipulating low-level code executed after successful exploitation.833 tools
  • ForensicsDigital forensics, evidence collection, timeline analysis, and incident investigation tools.857 tools
  • Post-ExploitationTools for maintaining access, exploring, and expanding control within compromised systems and networks.10820 tools
    • Privilege EscalationTools for gaining higher-level permissions or unauthorized access on compromised systems.3816 tools
    • Persistence MechanismsTools for maintaining long-term access to compromised systems, even after reboots.416 tools
    • Lateral MovementTools for exploring and expanding control within compromised networks by moving between systems.605 tools
    • Data ExfiltrationTools for extracting sensitive data from compromised systems without detection.646 tools
  • PhishingPhishing simulation, detection, analysis, and security awareness training tools.287 tools
  • Web SecurityTools for testing, exploiting, and securing web applications and APIs.31274 tools
    • Web Vulnerability ScannersAutomated tools for detecting common web application flaws (e.g., XSS, SQLi).296 tools
    • Web Proxies & InterceptionTools for intercepting, analyzing, and modifying web traffic for security testing.189 tools
    • Web Application ExploitationTools specifically designed to exploit common web application vulnerabilities (e.g., SQL injection, XSS).13163 tools
    • API Security TestingTools for assessing the security of REST, SOAP, and GraphQL APIs.328 tools
    • WAF BypassTools for finding and exploiting weaknesses in Web Application Firewalls to bypass their protections.259 tools
  • FuzzingFuzz testing, mutation-based, generation-based, and coverage-guided fuzzing tools.897 tools
  • Network SecurityTools for analyzing, monitoring, and securing network infrastructure and protocols.4193 tools
    • Packet Sniffing & AnalysisTools for capturing, inspecting, and analyzing network traffic in real-time or from capture files.349 tools
    • Port ScanningTools for discovering open ports, services, and potential entry points on network devices.289 tools
    • IDS/IPS EvasionTools for bypassing Intrusion Detection and Prevention Systems (IDS/IPS) and network security controls.622 tools
    • Network Access ControlTools for bypassing and testing network access controls (NAC) and authentication systems.12 tools
  • SteganographyData hiding, watermarking, steganalysis, and covert channel tools.105 tools
  • Wireless SecurityTools for auditing, testing, and securing Wi-Fi, Bluetooth, and RFID systems.1088 tools
    • Wi-Fi AuditingTools for testing Wi-Fi network security, cracking passwords, and analyzing protocols.221 tools
    • Bluetooth SecurityTools for assessing and exploiting Bluetooth device security and communication vulnerabilities.217 tools
    • RFID/NFC ToolsTools for analyzing, cloning, and interacting with RFID and NFC systems and tags.42 tools
  • Data RecoveryFile recovery, disk recovery, deleted data restoration, and forensic carving tools.128 tools
  • Malware AnalysisTools for dissecting, understanding, and reverse engineering malicious software behavior.6593 tools
    • Static AnalysisTools for examining malware binaries and code without executing them (e.g., disassemblers, unpackers).996 tools
    • Dynamic Analysis (Sandboxing)Tools for observing malware behavior in isolated environments to understand its actions and impact.558 tools
    • Reverse EngineeringTools for decompiling, disassembling, and understanding malware internals and complex binaries.1412 tools
    • DebuggersDebugging tools specifically for analyzing malware execution flow and identifying vulnerabilities.472 tools
  • Digital ForensicsTools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.1877 tools
    • Disk ForensicsTools for analyzing hard drives, SSDs, and other storage media to recover data and artifacts.54 tools
    • Memory ForensicsTools for analyzing RAM dumps to find running processes, network connections, and hidden malware.584 tools
    • Network ForensicsTools for analyzing network traffic and communication logs to investigate security incidents.120 tools
    • Mobile ForensicsTools for extracting, preserving, and analyzing data from mobile devices (smartphones, tablets).44 tools
  • Hardware HackingHardware hacking, modding, JTAG, UART, SPI, and embedded device exploitation tools.175 tools
  • CryptographyTools for implementing, analyzing, breaking, and implementing cryptographic systems and algorithms.3301 tools
    • Password CrackingTools for recovering passwords from hashes, encrypted sources, or through brute-force/dictionary attacks.585 tools
    • Encryption/Decryption ToolsTools for securely encrypting data or decrypting captured ciphertext and analyzing encryption methods.755 tools
    • Hash AnalysisTools for generating, analyzing, and cracking cryptographic hashes and checksums.158 tools
  • Penetration TestingPenetration testing methodologies, frameworks, reporting, and automation tools.19031 tools
  • Cloud SecurityTools for assessing, testing, and securing cloud environments (AWS, Azure, GCP) and their services.2697 tools
    • Cloud Infrastructure SecurityTools for auditing configurations, permissions, and services in cloud platforms (IaaS, PaaS).255 tools
    • Container SecurityTools for scanning, securing, and hardening Docker, Kubernetes, and containerized environments.741 tools
    • Serverless SecurityTools for testing and securing serverless functions (e.g., AWS Lambda, Azure Functions) and their integrations.18 tools
  • DevSecOpsSecurity integration in CI/CD pipelines, shift-left, and DevOps security automation tools.834 tools
  • Mobile SecurityTools for assessing, testing, and exploiting mobile applications and devices (Android, iOS).2741 tools
    • Android SecurityTools focused on penetration testing, reversing, and securing Android apps and the Android OS.968 tools
    • iOS SecurityTools focused on testing, reversing, and securing iOS applications and the iOS operating system.290 tools
    • Mobile App PentestingCross-platform tools and methodologies for comprehensive security testing of mobile applications.107 tools
  • PrivacyPrivacy-enhancing technologies, anonymity networks, and data minimization tools.340 tools
  • Command and ControlC2 frameworks, redirectors, listeners, and command infrastructure tools.2354 tools
  • Social EngineeringTools for simulating human-based attacks (phishing, pretexting, baiting) and testing human factors in security.1141 tools
    • Phishing ToolsTools for creating, managing, and analyzing fake login pages and email campaigns.332 tools
    • OSINT for Social EngineeringTools for gathering intelligence to support social engineering attacks and target profiling.43 tools
    • Impersonation ToolsTools for creating fake identities, spoofing communications, and impersonating targets for social engineering.89 tools
  • Hardware SecurityHardware security modules, TPM, secure enclave, and hardware trust tools.569 tools
  • Utilities & FrameworksGeneral-purpose tools, frameworks, and environments supporting various cybersecurity workflows and tasks.4512 tools
    • General Purpose UtilitiesMulti-purpose tools and utilities for various security tasks that don't fit specific categories.388 tools
    • Exploit FrameworksComprehensive frameworks for exploit development, testing, and execution.912 tools
    • Scripting & AutomationTools and libraries for automating security tasks, workflows, and custom tool development.677 tools
    • Security VirtualizationTools for creating and managing isolated environments (VMs, containers) for security testing and malware analysis.121 tools
  • Hardware & IoT SecurityTools for assessing the security of physical hardware, embedded systems, and IoT devices.2977 tools
    • Embedded Systems SecurityTools for analyzing and securing firmware, microcontrollers, and low-level hardware components.815 tools
    • IoT SecurityTools for testing and securing Internet of Things (IoT) devices, protocols, and platforms.691 tools
    • SCADA/ICS SecurityTools for assessing and securing Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS).105 tools
  • Secret DetectionAPI key scanning, credential leak detection, and secret management tools.349 tools
  • Binary AnalysisBinary reverse engineering, disassembly, decompilation, and patching tools.1335 tools
  • Threat IntelligenceTools for collecting, analyzing, and operationalizing threat feeds, indicators of compromise (IOCs), and attack trends.1796 tools
    • Indicator of Compromise (IOC) ManagementTools for managing, sharing, and integrating Indicators of Compromise (IOCs) into security defenses.306 tools
    • Threat Feeds & AggregatorsTools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.98 tools
  • Identity & Access Management (IAM)Tools for managing user identities, authentication, authorization, and access controls within systems and networks.1627 tools
    • Authentication & AuthorizationTools for testing and implementing authentication mechanisms (e.g., MFA, SSO) and authorization policies.742 tools
    • Identity ManagementTools for managing user lifecycle, provisioning, deprovisioning, and directories.12 tools
  • Supply Chain SecurityDependency scanning, SBOM generation, package integrity, and supply chain risk tools.671 tools
  • AuthenticationMFA, SSO, passwordless, biometric, and identity provider tools.1123 tools
  • Machine LearningML-based security tools, adversarial machine learning, and AI-powered cyber defense.248 tools
  • Intrusion DetectionIDS/IPS systems, network monitoring, anomaly-based detection, and threat alerting tools.537 tools
  • MisconfigurationConfiguration auditing, compliance scanning, hardening benchmarks, and drift detection tools.912 tools
  • Subdomain EnumerationSubdomain discovery, DNS brute-force, certificate transparency, and asset enumeration tools.279 tools
  • Email HarvestingEmail discovery, verification, pattern analysis, and OSINT email investigation tools.114 tools
  • Learning & EducationCybersecurity research, materials, labs, and learning paths, including CTFs and curated educational resources.15477 tools
    • CTFCapture The Flag platforms, challenge creation, solving tools, and competitive cybersecurity frameworks.982 tools
    • Papers & ResearchSecurity papers, research projects, technical references, and reproducible material for defensive or authorized analysis.1423 tools
    • Curated ResourcesCurated cybersecurity lists, collections, and learning references with clear scope and practical value.1147 tools
    • Learning Paths & CoursesCurricula, courses, and structured paths for learning cybersecurity, defensive security, and authorized testing.182 tools
    • Labs & PracticeTraining labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.2215 tools
  • AI-Assisted ReversingAI-powered decompilation, binary analysis, code summarization, and malware analysis tools.57 tools
  • DNS FuzzingDNS protocol fuzzing, mutation testing, resolver testing, and DNS security assessment tools.12 tools
  • Red TeamingAdversary simulation, red team infrastructure, C2 frameworks, and operational security tools.4741 tools
  • Incident ResponseIR playbooks, triage, case management, evidence collection, and incident management tools.1177 tools
  • CrawlerWeb crawling, scraping, spidering, and automated reconnaissance tools for security testing.287 tools
  • Remote Access ToolRAT development frameworks, detection tools, and post-exploitation remote access utilities.2133 tools
  • Shellcode GenerationShellcode generation, encoding, obfuscation, and testing frameworks.160 tools
  • Payload DevelopmentCustom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.3293 tools
  • Remote Access TrojanRAT analysis, detection signatures, behavioral analysis, and research frameworks.101 tools
  • API SecurityAPI testing, fuzzing, schema validation, authentication testing, and gateway security tools.380 tools
  • Anti-BotBot detection, CAPTCHA, rate limiting, behavioral analysis, and automated threat prevention tools.107 tools
  • Fingerprint SpoofingBrowser fingerprinting, TLS fingerprint evasion, device spoofing, and anti-fingerprinting tools.34 tools
  • CAPTCHA BypassCAPTCHA solving, automation, recognition, and testing tools for authorized research.29 tools
  • Email SecurityEmail filtering, DKIM/DMARC/SPF, anti-spam, phishing detection, and email gateway tools.176 tools
  • DNS AnalysisDNS reconnaissance, monitoring, tunneling detection, and DNS security analysis tools.609 tools
  • Chaos EngineeringResilience testing, fault injection, chaos experiments, and system reliability tools.5 tools
  • Container EscapeContainer breakout techniques, privilege escalation, and sandbox escape testing tools.181 tools
  • AI SecurityLLM security, prompt injection, model extraction, adversarial AI, and AI red teaming tools.541 tools
  • Database SecurityDatabase assessment, SQL injection testing, auditing, encryption, and activity monitoring tools.564 tools
  • Firmware AnalysisFirmware extraction, unpacking, emulation, vulnerability discovery, and binary analysis tools.398 tools
  • Anomaly DetectionBehavioral anomaly detection, outlier analysis, UEBA, and statistical threat detection tools.171 tools
  • Log AnalysisLog parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.561 tools
  • Adversarial AttackAdversarial ML attack frameworks, evasion techniques, and model robustness evaluation tools.282 tools
  • Binary ExploitationBinary exploitation techniques, ROP chains, heap exploitation, format strings, and memory corruption research.3863 tools