Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
CVE-2025-56219 preview

CVE-2025-56219

GitHubsaykino/cve-2025-56219

Detailed advisory for CVE-2025-56219, a rate-limiting flaw in Ascertia SigningHub's Add User API, enabling automated user creation and denial of…

api-securitycurated-resourceseducation+2
11 months ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k2 months ago
My-Presentation-Slides preview

My-Presentation-Slides

GitHubdhiyaneshgeek/my-presentation-slides

Collection's of Tech Talk that are presented by me :)

api-securitycloud-securitycurated-resources+6
1011 month ago
fireprox preview

fireprox

GitHubustayready/fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

api-securitycloud-securityinformation-gathering+5
2.3k4 years ago
CVE-2025-62727-Demo preview

CVE-2025-62727-Demo

GitHubch4n3-yoon/cve-2025-62727-demo

Proof of concept of CVE-2025-62727 that can cause denial-of-service in FastAPI (based Starlette <= 0.48.0)

api-securityexploitationvulnerability-analysis+1
110 months ago
Apache-APISIX-CVE-2022-24112 preview

Apache-APISIX-CVE-2022-24112

GitHubm4xsec/apache-apisix-cve-2022-24112

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

api-securityapi-security-testingexploitation+3
154 years ago
CVE-2025-56223 preview

CVE-2025-56223

GitHubsaykino/cve-2025-56223

Documentation of CVE-2025-56223, a denial-of-service vulnerability in Ascertia SigningHub's Upload Document API, allowing unrestricted file uploads…

api-securitypenetration-testingvulnerability-analysis+1
11 months ago
CVE-2025-66838 preview

CVE-2025-66838

GitHubsaykino/cve-2025-66838

Documentation of CVE-2025-66838: a rate-limiting vulnerability in ARIS file upload API allowing authenticated remote attackers to cause denial of…

api-securitymisconfigurationvulnerability-analysis+1
8 months ago
porch-pirate preview

porch-pirate

GitHubwatchdogsecurity/porch-pirate

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

api-securityinformation-gatheringosint+4
4772 years ago
CVE-2024-1208-and-CVE-2024-1210 preview

CVE-2024-1208-and-CVE-2024-1210

GitHubkarlemilnikka/cve-2024-1208-and-cve-2024-1210

Detailed disclosure of CVE-2024-1208 and CVE-2024-1210: sensitive information exposure via REST API in LearnDash WordPress plugin, allowing…

api-securityeducationinformation-gathering+3
32 years ago
CVE-2026-31283 preview

CVE-2026-31283

GitHubsaykino/cve-2026-31283

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

api-securityeducationemail-security+3
5 months ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.7k8h 19m ago
Arjun preview

Arjun

GitHubs0md3v/arjun

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

api-securityapi-security-testingfuzzing+3
6.4k1 year ago
kiterunner preview

kiterunner

GitHubassetnote/kiterunner

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

api-securityapi-security-testingdynamic-code-analysis+5
3.3k5 years ago
metlo preview

metlo

GitHubmetlo-labs/metlo

Metlo is an open-source API security platform.

api-securityapi-security-testingdefensive-tools+4
1.8k1 year ago
SentryPeer preview

SentryPeer

GitHubsentrypeer/sentrypeer

Distributed SIP honeypot that detects and shares fraud data on VoIP attacks. Collects bad actor IPs and phone numbers via peer-to-peer network, with…

api-securitynetwork-securitythreat-intelligence
21135 minutes ago
authproof-sdk preview

authproof-sdk

GitHubcommonguy25/authproof-sdk

Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof.

ai-securityapi-securityauthentication-authorization+3
62 months ago
CVE-2026-21020-Protobuf-Message-Parsing-Polymorphic-Deserialization-Vulnerability preview

CVE-2026-21020-Protobuf-Message-Parsing-Polymorphic-Deserialization-Vulnerability

GitHubgeorge0papasotiriou/cve-2026-21020-protobuf-message-parsing-polymorphic-deserialization-vulnerability

PoC for CVE-2026-21020, demonstrating Protobuf Any-type polymorphic deserialization where attacker-controlled type_url can lead to logic bugs, RCE,…

api-securityexploitationpenetration-testing+1
1 month ago
Previous12Next