Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

NewestRelevanceMost popularRecently updated
17039 results
CredSniper preview

CredSniper

GitHubustayready/credsniper

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

phishing-toolsweb-application-exploitationphishing+2
1.4k
6 years ago
nuclei-burp-plugin preview

nuclei-burp-plugin

GitHubprojectdiscovery/nuclei-burp-plugin

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

vulnerability-scannersapi-security-testingweb-security+2
1.3k10 months ago
reproxy preview

reproxy

GitHubumputun/reproxy

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

authentication-authorizationgeneral-purpose-utilitiesweb-security+2
1.3k11h 6m ago
Web-Cache-Vulnerability-Scanner preview

Web-Cache-Vulnerability-Scanner

GitHubhackmanit/web-cache-vulnerability-scanner

Go-based CLI scanner for web cache poisoning and deception. Supports 10 poisoning techniques, multiple deception methods, built-in crawler, JSON…

vulnerability-scannersweb-vulnerability-scannersweb-security+2
1.2k7 months ago
grapheneX preview

grapheneX

GitHubgraphenex/graphenex

Automated System Hardening Framework

defensive-toolsscripting-automationconfiguration-auditing+2
1.1k2 years ago
wordpress-exploit-framework preview
Archived

wordpress-exploit-framework

GitHubrastating/wordpress-exploit-framework

A Ruby framework designed to aid in the penetration testing of WordPress systems.

exploit-frameworksvulnerability-analysisshellcode+3
1.0k6 years ago
whitewidow preview
Archived

whitewidow

GitHubwhitewidowscanner/whitewidow

SQL Vulnerability Scanner

vulnerability-scannersweb-vulnerability-scannersweb-security+2
9828 years ago
vigolium preview

vigolium

GitHubvigolium/vigolium

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

vulnerability-scannersweb-vulnerability-scannersdynamic-analysis-sandboxing+9
9711 day ago
CVEs preview

CVEs

GitHubrhinosecuritylabs/cves

Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

authentication-authorizationprivilege-escalationvulnerability-analysis+3
9051 year ago
xalgorix preview

xalgorix

GitHubxalgord/xalgorix

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

reconnaissancevulnerability-scannersdynamic-analysis-sandboxing+7
8511 day ago
Cybersecurity-Books preview

Cybersecurity-Books

GitHubzealraj/cybersecurity-books

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

wi-fi-auditingreverse-engineeringweb-security+6
6784 years ago
ssrf-king preview

ssrf-king

GitHubethicalhackingplayground/ssrf-king

SSRF plugin for burp Automates SSRF Detection in all of the Request

vulnerability-scannersapi-security-testingweb-security+1
6335 years ago
Ashok preview

Ashok

GitHubpowerexploit/ashok

Ashok is a OSINT Recon Tool , a.k.a 😍 Swiss Army knife .

osintreconnaissanceinformation-gathering+4
4434 years ago
BypassFuzzer preview
Archived

BypassFuzzer

GitHubintrudir/bypassfuzzer

Fuzz 401/403/404 pages for bypasses

vulnerability-scannersids-ips-evasionweb-application-exploitation+3
4307 months ago
Burp2Malleable preview

Burp2Malleable

GitHubcodextf2/burp2malleable

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

web-proxies-interceptionids-ips-evasioncommand-and-control+2
4183 years ago
nosqli preview

nosqli

GitHubcharlie-belmer/nosqli

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

vulnerability-scannersweb-application-exploitationweb-security+1
4144 years ago
apidetector preview

apidetector

GitHubbrinhosa/apidetector

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

reconnaissancevulnerability-scannersapi-security-testing+2
3791 year ago
PhEmail preview

PhEmail

GitHubdionach/phemail

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

osintphishing-toolsweb-application-exploitation+4
3496 years ago
Previous1…567…947Next