Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
150 results
wardgate preview

wardgate

GitHubwardgate/wardgate

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

api-securityauthentication-authorizationcloud-security+8
136
6 months ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
CVE-2022-24112 preview

CVE-2022-24112

GitHubsecnn/cve-2022-24112

Apache APISIX batch-requests RCE(CVE-2022-24112)

api-securityexploitationremote-access-tool+2
84 years ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
1 month ago
fireprox preview

fireprox

GitHubustayready/fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

api-securitycloud-securityinformation-gathering+5
2.3k4 years ago
azureOutlookC2 preview

azureOutlookC2

GitHubboku7/azureoutlookc2

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

api-securitycloud-securitycommand-and-control+2
5033 years ago
cli preview

cli

GitHubcloudgraphdev/cli

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

api-securitycloud-infrastructure-securitycloud-security+3
8903 years ago
gimmepatz preview

gimmepatz

GitHub6mile/gimmepatz

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

api-securityauthentication-authorizationcloud-security+7
431 year ago
ginger preview

ginger

GitHubhawsec/ginger

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

api-securitydatabase-securityinformation-gathering+3
134 years ago
CVE-2026-58231 preview

CVE-2026-58231

GitHubwildandeveloper/cve-2026-58231

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

api-securityauthenticationinformation-gathering+4
24 days ago
UAP-protocol preview

UAP-protocol

GitHubrajsidwadkar/uap-protocol

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

api-securityauthentication-authorizationcloud-security+8
13 months ago
CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation preview

CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

GitHubackemed/cve-2026-1529-poc-keycloak-unauthorized-registration-via-improper-invitation-token-validation

Exploit tool for CVE-2026-1529, demonstrating unauthorized organization registration in Keycloak via JWT token manipulation. Includes token…

api-securityauthenticationexploitation+3
7 months ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
2579 months ago
tiny_tracer preview

tiny_tracer

GitHubhasherezade/tiny_tracer

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

api-securitybinary-analysisdynamic-analysis-sandboxing+2
1.7k3 months ago
gotestwaf preview

gotestwaf

GitHubwallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-securityapi-security-testingpenetration-testing+4
1.8k1 year ago
graphw00f preview

graphw00f

GitHubdolevf/graphw00f

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

api-securityapi-security-testingdynamic-code-analysis+5
9014 months ago
PwnedCheck preview

PwnedCheck

GitHubmohamedation/pwnedcheck

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.

api-securityencryption-decryption-toolspassword-cracking+3
33 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
26 months ago
Previous12…9Next