Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
xpfarm preview

xpfarm

GitHuba3-n/xpfarm

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

ai-securitybinary-analysiseducation+6
44
4 months ago
vulnrepo preview

vulnrepo

GitHubkac89/vulnrepo

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import…

ai-securitycurated-resourceseducation+4
5797 days ago
SubGPT preview
Archived

SubGPT

GitHubs0md3v/subgpt

Find subdomains with GPT, for free

ai-securitydns-subdomain-enumerationinformation-gathering+3
3572 years ago
buyer-eval-skill preview

buyer-eval-skill

GitHubsalespeak-ai/buyer-eval-skill

B2B software vendor evaluation skill for Claude Code — domain-expert questions, vendor AI agent conversations, evidence-based scoring

ai-securitycurated-resourceseducation+8
694 months ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
194 months ago
wp2shell-Hestia-Scanner preview

wp2shell-Hestia-Scanner

GitHubbytespulse-oe/wp2shell-hestia-scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

ai-securitydefensive-toolsforensics+7
21 month ago
See-SURF preview

See-SURF

GitHubin3tinct/see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

ai-securityreconnaissancevulnerability-scanners+2
3647 months ago
Syd preview

Syd

GitLabsydsec1/syd

Air-gapped cybersecurity assistant for security professionals. 100% offline AI-powered analysis tool for Nmap, Volatility, BloodHound, Metasploit,…

ai-securityeducationinformation-gathering+7
48 months ago
xpfarm preview

xpfarm

GitHubcanuk40/xpfarm

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

ai-securitybinary-analysisexploit-frameworks+7
1955 months ago
Recon-Scan preview

Recon-Scan

GitHubaarocy/recon-scan

Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.

ai-securitydns-analysisdns-subdomain-enumeration+6
71 month ago
GPT_Vuln-analyzer preview

GPT_Vuln-analyzer

GitHubmorpheuslord/gpt_vuln-analyzer

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

ai-securitydns-analysisdns-subdomain-enumeration+7
5991 year ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

ai-securitycommand-and-controldata-exfiltration+7
3713 months ago
hephaestus-server-forger preview

hephaestus-server-forger

GitHubrodhnin/hephaestus-server-forger

server security auditor scanning Apache, Nginx, and IIS configurations with AI-powered hardening guides and professional reporting.

ai-securitycloud-securityconfiguration-auditing+4
14 months ago
shannon preview

shannon

GitHubkeygraphhq/shannon

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

ai-securityapi-security-testingcode-analysis+5
48.0k5 days ago
garak preview

garak

GitHubnvidia/garak

Modular LLM vulnerability scanner that probes for hallucination, data leakage, prompt injection, jailbreaks, and toxicity using static, dynamic, and…

adversarial-attackai-securityeducation+5
9.2k4 days ago
cai preview

cai

GitHubaliasrobotics/cai

Cybersecurity AI (CAI), the framework for AI Security

ai-securityctfeducation+8
9.8k23 days ago
pentestagent preview

pentestagent

GitHubgh05tcrew/pentestagent

AI agent framework for black-box security testing with autonomous multi-agent orchestration, built-in pentesting tools, and MCP integration for bug…

ai-securityctfeducation+8
3.1k7 days ago
redamon preview

redamon

GitHubsamugit83/redamon

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

ai-securityexploit-frameworkslateral-movement+8
2.4k1 day ago
Previous1234567Next