Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
359 results
maps_scanner preview

maps_scanner

GitHubhackinglz/maps_scanner

MAPS cloud scanner and response parser for Microsoft Defender research.

api-security-testingdynamic-analysis-sandboxingfuzzing+6
95
6 months ago
CobraAudit preview

CobraAudit

GitHubjakkxbt/cobraaudit

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

api-security-testingauthenticationpenetration-testing+2
61 month ago
API-SPY-API-PROBE preview

API-SPY-API-PROBE

GitHubaustinjump-sec/api-spy-api-probe

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

api-security-testingcrawlerinformation-gathering+4
53 months ago
RatRace preview

RatRace

GitHubbogdanticu88/ratrace

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

api-security-testingdevsecopsexploitation+5
104 months ago
alexafaraday preview

alexafaraday

GitHubinfobyte/alexafaraday

Alexa skill example for Faraday API

api-security-testingpenetration-testingscripting-automation+2
57 years ago
CVE-2026-54356 preview

CVE-2026-54356

GitHubkovachvl/cve-2026-54356

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

api-security-testingcloud-securityexploitation+3
23 days ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
24 days ago
ragflow-audit preview

ragflow-audit

GitHubqianlijaingshan/ragflow-audit

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

api-security-testingexploitationpenetration-testing+4
126 days ago
CVE-2026-55255-Lab preview

CVE-2026-55255-Lab

GitHubrootdirective-sec/cve-2026-55255-lab

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

api-security-testingeducationlabs-practice+3
2 months ago
CVE-2025-34291_cors_security_scanner preview

CVE-2025-34291_cors_security_scanner

GitHubamnnrth/cve-2025-34291_cors_security_scanner

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

api-security-testingmisconfigurationpenetration-testing+3
3 months ago
bola-CVE-2023-27524 preview

bola-CVE-2023-27524

GitHubrachidafaf/bola-cve-2023-27524

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

api-security-testingauthentication-authorizationeducation+3
5 months ago
CVE-2021-4191_Exploits preview

CVE-2021-4191_Exploits

GitHubadelittle/cve-2021-4191_exploits

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

api-security-testingexploitationinformation-gathering+3
3 years ago
ExtendedMacro preview
Archived

ExtendedMacro

GitHubfruh/extendedmacro

ExtendedMacro - BurpSuite plugin providing extended macro functionality

api-security-testingpenetration-testingscripting-automation+3
155 years ago
raider preview
Archived

raider

GitHubdigeex/raider

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

api-security-testingauthenticationpenetration-testing+1
1394 years ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.0k2 days ago
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.6k17 days ago
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.4k2 days ago
Arjun preview

Arjun

GitHubs0md3v/arjun

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

api-securityapi-security-testingfuzzing+3
6.4k1 year ago
Previous1…345…20Next