Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
461 results
openapi-parser preview

openapi-parser

GitHubaress31/openapi-parser

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

api-securityapi-security-testingpenetration-testing+2
209
2 years ago
opentaint preview

opentaint

GitHubseqra/opentaint

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

ai-securityapi-securitycode-analysis+7
1604 days ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4081 year ago
Spring-Cloud-Gateway-CVE-2022-22947 preview

Spring-Cloud-Gateway-CVE-2022-22947

GitHublucksec/spring-cloud-gateway-cve-2022-22947

Exploit for CVE-2022-22947: remote code execution in Spring Cloud Gateway via crafted requests to the Actuator endpoint. Includes Python script and…

api-securitycode-analysisexploitation+3
2234 years ago
not-going-anywhere preview

not-going-anywhere

GitHubtrailofbits/not-going-anywhere

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

api-securitydatabase-securityeducation+3
1783 years ago
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

api-securityapi-security-testingauthentication-authorization+6
1801 year ago
talos preview

talos

GitHubory/talos

Scalable API key server for issuing, verifying, and revoking credentials with token derivation for fine-grained capability tokens. Supports…

api-securityauthentication-authorizationcloud-security+3
1982 months ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
2579 months ago
My-Presentation-Slides preview

My-Presentation-Slides

GitHubdhiyaneshgeek/my-presentation-slides

Collection's of Tech Talk that are presented by me :)

api-securitycloud-securitycurated-resources+6
1011 month ago
ibmsecurity preview

ibmsecurity

GitHubibm-security/ibmsecurity

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

api-securityconfiguration-auditingdevsecops+3
532 months ago
cve-2021-45232-exp preview

cve-2021-45232-exp

GitHubwuppp/cve-2021-45232-exp

Exploit for CVE-2021-45232 targeting Apache APISIX Dashboard remote code execution vulnerability. Provides proof-of-concept for security testing and…

api-securityexploitationpenetration-testing+2
784 years ago
wardgate preview

wardgate

GitHubwardgate/wardgate

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

api-securityauthentication-authorizationcloud-security+8
1366 months ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
filtron preview

filtron

GitHubasciimoo/filtron

Filtering reverse HTTP proxy

api-securitydefensive-toolsweb-security
1743 years ago
vaas preview

vaas

GitHubgdatasoftwareag/vaas

Verdict-as-a-Service SDKs: Analyze files for malicious content

api-securitycloud-securitymalware-analysis+1
383 months ago
CVE-2022-1388_PoC preview

CVE-2022-1388_PoC

GitHubalt3kx/cve-2022-1388_poc

F5 BIG-IP RCE exploitation (CVE-2022-1388)

api-securityauthenticationexploitation+3
874 years ago
FlowAnalyzer preview

FlowAnalyzer

GitHubmanuelberrueta/flowanalyzer

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

api-securityapi-security-testingauthentication-authorization+5
1842 years ago
mcp-shark preview

mcp-shark

GitHubmcp-shark/mcp-shark

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

ai-securityapi-securityconfiguration-auditing+7
1795 months ago
Previous1…789…26Next