Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
372 results
rep-chrome preview

rep-chrome

GitHubrepplus/rep-chrome

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

ai-securityapi-security-testingfuzzing+6
1.6k
8 months ago
apicheck preview

apicheck

GitHubowasp/apicheck

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

api-securityapi-security-testingdevsecops+3
371 year ago
firefox-devtools-mcp preview

firefox-devtools-mcp

GitHubmozilla/firefox-devtools-mcp

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

android-securityapi-security-testingdebuggers+7
4262 days ago
GraphQLmap preview

GraphQLmap

GitHubswisskyrepo/graphqlmap

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

api-security-testingctffuzzing+3
1.7k3 years ago
api-scanner-docker preview

api-scanner-docker

GitHubcspf-founder/api-scanner-docker

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

api-securityapi-security-testingconfiguration-auditing+5
97 months ago
CVE-2026-53625-GLPI-PoC preview

CVE-2026-53625-GLPI-PoC

GitHub7h30th3r0n3/cve-2026-53625-glpi-poc

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

api-security-testingauthentication-authorizationexploitation+4
1 month ago
CVE-2025-45809-PoC preview

CVE-2025-45809-PoC

GitHublearner202649/cve-2025-45809-poc

Time-based blind SQL injection proof-of-concept for LiteLLM v1.65.4. Exploits the `/key/block` endpoint to extract database contents and read server…

api-security-testingdatabase-securityeducation+3
3 months ago
GraphQLGrapper preview

GraphQLGrapper

GitHubm19o/graphqlgrapper

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

api-security-testinginformation-gatheringpenetration-testing+3
211 year ago
CVE-2026-41473-CyberPanel-AI-Scanner-Unauth preview

CVE-2026-41473-CyberPanel-AI-Scanner-Unauth

GitHubpenteraio/cve-2026-41473-cyberpanel-ai-scanner-unauth

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

api-securityapi-security-testingvulnerability-analysis+3
3 months ago
http-desync-guardian preview

http-desync-guardian

GitHubaws/http-desync-guardian

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

api-security-testingstatic-analysisvulnerability-analysis+1
2743 months ago
CVE-2026-30944-PoC preview

CVE-2026-30944-PoC

GitHubfilipegaudard/cve-2026-30944-poc

Python proof-of-concept for CVE-2026-30944, exploiting a BOLA vulnerability in StudioCMS to escalate privileges via insecure API token generation.

api-security-testingexploitationpenetration-testing+4
6 months ago
CVE-2023-45857-Demo preview

CVE-2023-45857-Demo

GitHubfuyuooumi1027/cve-2023-45857-demo

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

api-security-testingctfeducation+3
12 years ago
graphicator preview

graphicator

GitHubcybervelia/graphicator

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

api-security-testinginformation-gatheringpenetration-testing+1
1343 years ago
CVE-2023-27532 preview

CVE-2023-27532

GitHubhorizon3ai/cve-2023-27532

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

api-security-testingexploitationpenetration-testing+2
743 years ago
waf-tester preview

waf-tester

GitHubkpomin57/waf-tester

A program for testing WAF functionality

api-security-testingeducationids-ips-evasion+5
264 months ago
CVE2022-1388_TestAPI preview

CVE2022-1388_TestAPI

GitHubbandit92/cve2022-1388_testapi

A Test API for testing the POC against CVE-2022-1388

api-security-testingexploitationpenetration-testing+2
44 years ago
URL_CHECKER preview

URL_CHECKER

GitHubmannansainicyber/url_checker

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

api-security-testingeducationmachine-learning+3
16 months ago
mcpsnoop preview

mcpsnoop

GitHubkerlenton/mcpsnoop

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

api-security-testingdebuggersdynamic-analysis-sandboxing+5
3549 days ago
Previous1…345…21Next