Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Categories

Browse cybersecurity tools by security context and purpose.

Categories

  • Defensive ToolsTools for blue team, defensive security, and threat protection.1130 tools
  • ReconnaissanceTools for gathering information about targets and identifying attack surfaces.15369 tools
    • OSINT (Open Source Intelligence)Tools for collecting and analyzing publicly available information from online sources.1246 tools
    • Network MappingTools for discovering network topology, devices, and services.476 tools
    • DNS & Subdomain EnumerationTools for discovering subdomains and DNS records associated with target domains.218 tools
    • Information GatheringGeneral purpose tools for collecting various types of information about targets.6068 tools
  • Password AttacksPassword cracking, brute-force, wordlists, and credential testing tools.876 tools
  • Vulnerability AnalysisTools for identifying, assessing, and prioritizing security weaknesses in systems and applications.32484 tools
    • Vulnerability ScannersAutomated tools for detecting known vulnerabilities in systems and applications.3618 tools
    • Static Code Analysis (SAST)Tools for examining source code without execution to find security flaws.153 tools
    • Dynamic Code Analysis (DAST)Tools for analyzing application behavior during runtime to find security vulnerabilities.123 tools
    • Configuration AuditingTools for reviewing system and application configurations for security weaknesses and compliance.967 tools
  • Code AnalysisStatic and dynamic code analysis, SAST, DAST, and code review tools.2072 tools
  • ExploitationTools for weaponizing vulnerabilities to gain unauthorized access to systems or data.29906 tools
    • Penetration Testing FrameworksIntegrated platforms for developing, executing, and managing penetration tests.384 tools
    • Payload GenerationTools for creating and customizing malicious code or instructions to execute after exploitation.3427 tools
    • ShellcodeTools for crafting and manipulating low-level code executed after successful exploitation.841 tools
  • ForensicsDigital forensics, evidence collection, timeline analysis, and incident investigation tools.903 tools
  • Post-ExploitationTools for maintaining access, exploring, and expanding control within compromised systems and networks.11817 tools
    • Privilege EscalationTools for gaining higher-level permissions or unauthorized access on compromised systems.4222 tools
    • Persistence MechanismsTools for maintaining long-term access to compromised systems, even after reboots.447 tools
    • Lateral MovementTools for exploring and expanding control within compromised networks by moving between systems.633 tools
    • Data ExfiltrationTools for extracting sensitive data from compromised systems without detection.689 tools
  • PhishingPhishing simulation, detection, analysis, and security awareness training tools.316 tools
  • Web SecurityTools for testing, exploiting, and securing web applications and APIs.33736 tools
    • Web Vulnerability ScannersAutomated tools for detecting common web application flaws (e.g., XSS, SQLi).313 tools
    • Web Proxies & InterceptionTools for intercepting, analyzing, and modifying web traffic for security testing.214 tools
    • Web Application ExploitationTools specifically designed to exploit common web application vulnerabilities (e.g., SQL injection, XSS).14135 tools
    • API Security TestingTools for assessing the security of REST, SOAP, and GraphQL APIs.367 tools
    • WAF BypassTools for finding and exploiting weaknesses in Web Application Firewalls to bypass their protections.281 tools
  • FuzzingFuzz testing, mutation-based, generation-based, and coverage-guided fuzzing tools.950 tools
  • Network SecurityTools for analyzing, monitoring, and securing network infrastructure and protocols.4562 tools
    • Packet Sniffing & AnalysisTools for capturing, inspecting, and analyzing network traffic in real-time or from capture files.377 tools
    • Port ScanningTools for discovering open ports, services, and potential entry points on network devices.317 tools
    • IDS/IPS EvasionTools for bypassing Intrusion Detection and Prevention Systems (IDS/IPS) and network security controls.643 tools
    • Network Access ControlTools for bypassing and testing network access controls (NAC) and authentication systems.32 tools
  • SteganographyData hiding, watermarking, steganalysis, and covert channel tools.119 tools
  • Wireless SecurityTools for auditing, testing, and securing Wi-Fi, Bluetooth, and RFID systems.1197 tools
    • Wi-Fi AuditingTools for testing Wi-Fi network security, cracking passwords, and analyzing protocols.229 tools
    • Bluetooth SecurityTools for assessing and exploiting Bluetooth device security and communication vulnerabilities.242 tools
    • RFID/NFC ToolsTools for analyzing, cloning, and interacting with RFID and NFC systems and tags.58 tools
  • Data RecoveryFile recovery, disk recovery, deleted data restoration, and forensic carving tools.153 tools
  • Malware AnalysisTools for dissecting, understanding, and reverse engineering malicious software behavior.7148 tools
    • Static AnalysisTools for examining malware binaries and code without executing them (e.g., disassemblers, unpackers).1072 tools
    • Dynamic Analysis (Sandboxing)Tools for observing malware behavior in isolated environments to understand its actions and impact.594 tools
    • Reverse EngineeringTools for decompiling, disassembling, and understanding malware internals and complex binaries.1544 tools
    • DebuggersDebugging tools specifically for analyzing malware execution flow and identifying vulnerabilities.496 tools
  • Digital ForensicsTools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.2084 tools
    • Disk ForensicsTools for analyzing hard drives, SSDs, and other storage media to recover data and artifacts.73 tools
    • Memory ForensicsTools for analyzing RAM dumps to find running processes, network connections, and hidden malware.621 tools
    • Network ForensicsTools for analyzing network traffic and communication logs to investigate security incidents.137 tools
    • Mobile ForensicsTools for extracting, preserving, and analyzing data from mobile devices (smartphones, tablets).62 tools
  • Hardware HackingHardware hacking, modding, JTAG, UART, SPI, and embedded device exploitation tools.210 tools
  • CryptographyTools for implementing, analyzing, breaking, and implementing cryptographic systems and algorithms.3502 tools
    • Password CrackingTools for recovering passwords from hashes, encrypted sources, or through brute-force/dictionary attacks.602 tools
    • Encryption/Decryption ToolsTools for securely encrypting data or decrypting captured ciphertext and analyzing encryption methods.797 tools
    • Hash AnalysisTools for generating, analyzing, and cracking cryptographic hashes and checksums.177 tools
  • Penetration TestingPenetration testing methodologies, frameworks, reporting, and automation tools.20310 tools
  • Cloud SecurityTools for assessing, testing, and securing cloud environments (AWS, Azure, GCP) and their services.3092 tools
    • Cloud Infrastructure SecurityTools for auditing configurations, permissions, and services in cloud platforms (IaaS, PaaS).349 tools
    • Container SecurityTools for scanning, securing, and hardening Docker, Kubernetes, and containerized environments.821 tools
    • Serverless SecurityTools for testing and securing serverless functions (e.g., AWS Lambda, Azure Functions) and their integrations.35 tools
  • DevSecOpsSecurity integration in CI/CD pipelines, shift-left, and DevOps security automation tools.975 tools
  • Mobile SecurityTools for assessing, testing, and exploiting mobile applications and devices (Android, iOS).3048 tools
    • Android SecurityTools focused on penetration testing, reversing, and securing Android apps and the Android OS.1067 tools
    • iOS SecurityTools focused on testing, reversing, and securing iOS applications and the iOS operating system.324 tools
    • Mobile App PentestingCross-platform tools and methodologies for comprehensive security testing of mobile applications.136 tools
  • PrivacyPrivacy-enhancing technologies, anonymity networks, and data minimization tools.385 tools
  • Command and ControlC2 frameworks, redirectors, listeners, and command infrastructure tools.2441 tools
  • Social EngineeringTools for simulating human-based attacks (phishing, pretexting, baiting) and testing human factors in security.1234 tools
    • Phishing ToolsTools for creating, managing, and analyzing fake login pages and email campaigns.349 tools
    • OSINT for Social EngineeringTools for gathering intelligence to support social engineering attacks and target profiling.63 tools
    • Impersonation ToolsTools for creating fake identities, spoofing communications, and impersonating targets for social engineering.109 tools
  • Hardware SecurityHardware security modules, TPM, secure enclave, and hardware trust tools.623 tools
  • Utilities & FrameworksGeneral-purpose tools, frameworks, and environments supporting various cybersecurity workflows and tasks.5459 tools
    • General Purpose UtilitiesMulti-purpose tools and utilities for various security tasks that don't fit specific categories.450 tools
    • Exploit FrameworksComprehensive frameworks for exploit development, testing, and execution.1223 tools
    • Scripting & AutomationTools and libraries for automating security tasks, workflows, and custom tool development.734 tools
    • Security VirtualizationTools for creating and managing isolated environments (VMs, containers) for security testing and malware analysis.162 tools
  • Hardware & IoT SecurityTools for assessing the security of physical hardware, embedded systems, and IoT devices.3278 tools
    • Embedded Systems SecurityTools for analyzing and securing firmware, microcontrollers, and low-level hardware components.882 tools
    • IoT SecurityTools for testing and securing Internet of Things (IoT) devices, protocols, and platforms.759 tools
    • SCADA/ICS SecurityTools for assessing and securing Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS).128 tools
  • Secret DetectionAPI key scanning, credential leak detection, and secret management tools.371 tools
  • Binary AnalysisBinary reverse engineering, disassembly, decompilation, and patching tools.1470 tools
  • Threat IntelligenceTools for collecting, analyzing, and operationalizing threat feeds, indicators of compromise (IOCs), and attack trends.1956 tools
    • Indicator of Compromise (IOC) ManagementTools for managing, sharing, and integrating Indicators of Compromise (IOCs) into security defenses.332 tools
    • Threat Feeds & AggregatorsTools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.115 tools
  • Identity & Access Management (IAM)Tools for managing user identities, authentication, authorization, and access controls within systems and networks.1813 tools
    • Authentication & AuthorizationTools for testing and implementing authentication mechanisms (e.g., MFA, SSO) and authorization policies.818 tools
    • Identity ManagementTools for managing user lifecycle, provisioning, deprovisioning, and directories.31 tools
  • Supply Chain SecurityDependency scanning, SBOM generation, package integrity, and supply chain risk tools.760 tools
  • AuthenticationMFA, SSO, passwordless, biometric, and identity provider tools.1297 tools
  • Machine LearningML-based security tools, adversarial machine learning, and AI-powered cyber defense.307 tools
  • Intrusion DetectionIDS/IPS systems, network monitoring, anomaly-based detection, and threat alerting tools.582 tools
  • MisconfigurationConfiguration auditing, compliance scanning, hardening benchmarks, and drift detection tools.946 tools
  • Subdomain EnumerationSubdomain discovery, DNS brute-force, certificate transparency, and asset enumeration tools.301 tools
  • Email HarvestingEmail discovery, verification, pattern analysis, and OSINT email investigation tools.128 tools
  • Learning & EducationCybersecurity research, materials, labs, and learning paths, including CTFs and curated educational resources.17007 tools
    • CTFCapture The Flag platforms, challenge creation, solving tools, and competitive cybersecurity frameworks.1044 tools
    • Papers & ResearchSecurity papers, research projects, technical references, and reproducible material for defensive or authorized analysis.1619 tools
    • Curated ResourcesCurated cybersecurity lists, collections, and learning references with clear scope and practical value.1392 tools
    • Learning Paths & CoursesCurricula, courses, and structured paths for learning cybersecurity, defensive security, and authorized testing.205 tools
    • Labs & PracticeTraining labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.2400 tools
  • AI-Assisted ReversingAI-powered decompilation, binary analysis, code summarization, and malware analysis tools.80 tools
  • DNS FuzzingDNS protocol fuzzing, mutation testing, resolver testing, and DNS security assessment tools.31 tools
  • Red TeamingAdversary simulation, red team infrastructure, C2 frameworks, and operational security tools.5157 tools
  • Incident ResponseIR playbooks, triage, case management, evidence collection, and incident management tools.1312 tools
  • CrawlerWeb crawling, scraping, spidering, and automated reconnaissance tools for security testing.312 tools
  • Remote Access ToolRAT development frameworks, detection tools, and post-exploitation remote access utilities.2230 tools
  • Shellcode GenerationShellcode generation, encoding, obfuscation, and testing frameworks.176 tools
  • Payload DevelopmentCustom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.3560 tools
  • Remote Access TrojanRAT analysis, detection signatures, behavioral analysis, and research frameworks.139 tools
  • API SecurityAPI testing, fuzzing, schema validation, authentication testing, and gateway security tools.448 tools
  • Anti-BotBot detection, CAPTCHA, rate limiting, behavioral analysis, and automated threat prevention tools.131 tools
  • Fingerprint SpoofingBrowser fingerprinting, TLS fingerprint evasion, device spoofing, and anti-fingerprinting tools.49 tools
  • CAPTCHA BypassCAPTCHA solving, automation, recognition, and testing tools for authorized research.42 tools
  • Email SecurityEmail filtering, DKIM/DMARC/SPF, anti-spam, phishing detection, and email gateway tools.208 tools
  • DNS AnalysisDNS reconnaissance, monitoring, tunneling detection, and DNS security analysis tools.634 tools
  • Chaos EngineeringResilience testing, fault injection, chaos experiments, and system reliability tools.22 tools
  • Container EscapeContainer breakout techniques, privilege escalation, and sandbox escape testing tools.214 tools
  • AI SecurityLLM security, prompt injection, model extraction, adversarial AI, and AI red teaming tools.646 tools
  • Database SecurityDatabase assessment, SQL injection testing, auditing, encryption, and activity monitoring tools.618 tools
  • Firmware AnalysisFirmware extraction, unpacking, emulation, vulnerability discovery, and binary analysis tools.445 tools
  • Anomaly DetectionBehavioral anomaly detection, outlier analysis, UEBA, and statistical threat detection tools.206 tools
  • Log AnalysisLog parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.627 tools
  • Adversarial AttackAdversarial ML attack frameworks, evasion techniques, and model robustness evaluation tools.324 tools
  • Binary ExploitationBinary exploitation techniques, ROP chains, heap exploitation, format strings, and memory corruption research.4222 tools