Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Advanced web path brute-forcer for discovering hidden directories and files. Supports recursive scanning, custom wordlists, filters, proxies, and…

api-securityapi-security-testingcrawler+11
14.7k
10h 17m ago
ffuf preview

ffuf

GitHubffuf/ffuf

High-performance web fuzzer for content discovery, virtual host enumeration, and parameter fuzzing. Supports recursive scanning, multi-wordlist…

api-securityapi-security-testingcrawler+12
16.6k5 days ago
keyFinder preview

keyFinder

GitHubmomenbasel/keyfinder

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

api-securityinformation-gatheringosint+2
7011 month ago
mitmproxy2swagger preview

mitmproxy2swagger

GitHubalufers/mitmproxy2swagger

Automagically reverse-engineer REST APIs via capturing traffic

api-securityinformation-gatheringreverse-engineering+1
9.6k2 months ago
CVE-2026-32646 preview

CVE-2026-32646

GitHubmichaeladamgroberman/cve-2026-32646

CVE-2026-32646 disclosure detailing missing authentication on Gardyn Home Kit administrative device management API endpoint, enabling unauthenticated…

api-securityauthenticationcloud-security+6
2 months ago
CVE-2026-25197 preview

CVE-2026-25197

GitHubmichaeladamgroberman/cve-2026-25197

Detailed disclosure of CVE-2026-25197: Authorization bypass via IDOR in Gardyn Home Kit cloud API, exposing PII and camera images of 134K+ users…

api-securityeducationinformation-gathering+6
2 months ago
web3-decoder preview

web3-decoder

GitHubnccgroup/web3-decoder

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

api-securityinformation-gatheringpenetration-testing+3
1152 months ago
CVE-2026-44595 preview

CVE-2026-44595

GitHubex-cal1bur/cve-2026-44595

Proof-of-concept exploit for CVE-2026-44595 demonstrating unauthorized user enumeration via missing authorization checks in YAMCS IAM API endpoints.

api-securityauthentication-authorizationexploitation+3
2 months ago
SwaggerSpy preview

SwaggerSpy

GitHubundeadsec/swaggerspy

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

api-securityinformation-gatheringosint+1
3183 months ago
graphw00f preview

graphw00f

GitHubdolevf/graphw00f

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

api-securityapi-security-testingdynamic-code-analysis+5
8913 months ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.0k4 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
25 months ago
censys-python preview

censys-python

GitHubcensys/censys-python

An easy-to-use and lightweight API wrapper for Censys APIs.

api-securityinformation-gatheringosint+2
4688 months ago
CVE-2025-59843-CVE-2025-59932 preview

CVE-2025-59843-CVE-2025-59932

GitHubat0mxploit/cve-2025-59843-cve-2025-59932

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

api-securityinformation-gatheringmisconfiguration+3
111 months ago
CVE-2025-54554 preview

CVE-2025-54554

GitHubaman-parmar/cve-2025-54554

Advisory detailing an unauthenticated REST API information disclosure vulnerability in tiaudit, including impact, attack vector, and vendor fix…

api-securityinformation-gatheringmisconfiguration+2
1 year ago
CVE-2025-51869 preview

CVE-2025-51869

GitHubsecsys-fdu/cve-2025-51869

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Liner's chat component, allowing attackers to tamper with other users'…

api-securityinformation-gatheringpenetration-testing+3
11 year ago
CVE-2024-46635 preview

CVE-2024-46635

GitHubh1thub/cve-2024-46635

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

api-securityinformation-gatheringmisconfiguration+3
11 year ago
porch-pirate preview

porch-pirate

GitHubwatchdogsecurity/porch-pirate

Automated OSINT and reconnaissance framework for Postman that discovers API endpoints, secrets, and sensitive data across workspaces, collections,…

api-securityinformation-gatheringosint+4
4682 years ago
Previous12Next