Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
web3-decoder preview

web3-decoder

GitHubnccgroup/web3-decoder

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

api-securityinformation-gatheringpenetration-testing+3
115
2 months ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Advanced web path brute-forcer for discovering hidden directories and files. Supports recursive scanning, custom wordlists, filters, proxies, and…

api-securityapi-security-testingcrawler+11
14.7k10h 9m ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.0k4 months ago
graphw00f preview

graphw00f

GitHubdolevf/graphw00f

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

api-securityapi-security-testingdynamic-code-analysis+5
8913 months ago
ffuf preview

ffuf

GitHubffuf/ffuf

High-performance web fuzzer for content discovery, virtual host enumeration, and parameter fuzzing. Supports recursive scanning, multi-wordlist…

api-securityapi-security-testingcrawler+12
16.6k5 days ago
CVE-2026-25197 preview

CVE-2026-25197

GitHubmichaeladamgroberman/cve-2026-25197

Detailed disclosure of CVE-2026-25197: Authorization bypass via IDOR in Gardyn Home Kit cloud API, exposing PII and camera images of 134K+ users…

api-securityeducationinformation-gathering+6
2 months ago
CVE-2026-44595 preview

CVE-2026-44595

GitHubex-cal1bur/cve-2026-44595

Proof-of-concept exploit for CVE-2026-44595 demonstrating unauthorized user enumeration via missing authorization checks in YAMCS IAM API endpoints.

api-securityauthentication-authorizationexploitation+3
2 months ago
CVE-2026-32646 preview

CVE-2026-32646

GitHubmichaeladamgroberman/cve-2026-32646

CVE-2026-32646 disclosure detailing missing authentication on Gardyn Home Kit administrative device management API endpoint, enabling unauthenticated…

api-securityauthenticationcloud-security+6
2 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
25 months ago
mitmproxy2swagger preview

mitmproxy2swagger

GitHubalufers/mitmproxy2swagger

Automagically reverse-engineer REST APIs via capturing traffic

api-securityinformation-gatheringreverse-engineering+1
9.6k2 months ago
keyFinder preview

keyFinder

GitHubmomenbasel/keyfinder

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

api-securityinformation-gatheringosint+2
7011 month ago
porch-pirate preview

porch-pirate

GitHubwatchdogsecurity/porch-pirate

Automated OSINT and reconnaissance framework for Postman that discovers API endpoints, secrets, and sensitive data across workspaces, collections,…

api-securityinformation-gatheringosint+4
4682 years ago
SwaggerSpy preview

SwaggerSpy

GitHubundeadsec/swaggerspy

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

api-securityinformation-gatheringosint+1
3183 months ago
censys-python preview

censys-python

GitHubcensys/censys-python

An easy-to-use and lightweight API wrapper for Censys APIs.

api-securityinformation-gatheringosint+2
4688 months ago
swaggerHole preview

swaggerHole

GitHubliodeus/swaggerhole

A python3 script searching for secret on swaggerhub

api-securityinformation-gatheringosint+2
664 years ago
Cve-api preview

Cve-api

GitHubbeyarz/cve-api

Self-hosted API to parse, filter, and query the latest CVEs from cve.mitre.org by keyword and year, enabling real-time vulnerability intelligence.

api-securityinformation-gatheringthreat-intelligence+1
404 years ago
super-secret-finder preview

super-secret-finder

GitHubrandomrobbiebf/super-secret-finder

Automated secret matching plugin for Burp Suite that detects exposed API keys, tokens, and credentials in HTTP requests and responses for security…

api-securityinformation-gatheringpenetration-testing+3
63 years ago
CVE-2025-59843-CVE-2025-59932 preview

CVE-2025-59843-CVE-2025-59932

GitHubat0mxploit/cve-2025-59843-cve-2025-59932

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

api-securityinformation-gatheringmisconfiguration+3
111 months ago
Previous12Next