Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
wahh_extras preview

wahh_extras

GitHubsix2dez/wahh_extras

The Web Application Hacker's Handbook - Extra Content

curated-resourceseducationlearning-paths-courses+2
571
3 years ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.4k15h 25m ago
awesome-web-hacking preview

awesome-web-hacking

GitHubinfoslack/awesome-web-hacking

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

cryptographyctfcurated-resources+6
7.2k14 days ago
Awesome-WAF preview

Awesome-WAF

GitHub0xinfection/awesome-waf

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

curated-resourceseducationwaf-bypass+1
7.6k1 day ago
Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes preview

Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes

GitHubxalgord/massive-web-application-penetration-testing-bug-bounty-notes

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

curated-resourceseducationlearning-paths-courses+3
1.8k11 months ago
google-dorks-bug-bounty preview

google-dorks-bug-bounty

GitHubtaksec/google-dorks-bug-bounty

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

curated-resourcesinformation-gatheringosint+2
1.9k11 months ago
api_wordlist preview

api_wordlist

GitHubchrislockard/api_wordlist

A wordlist of API names for web application assessments

api-security-testingcurated-resourcesfuzzing+2
9271 year ago
decider preview

decider

GitHubcisagov/decider

A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE ATT&CK®…

curated-resourceseducationpenetration-testing+1
1.2k1 year ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5502 years ago
Vulnerability_PoC preview

Vulnerability_PoC

GitHubnumencyber/vulnerability_poc

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

binary-exploitationcurated-resourceseducation+3
3314 months ago
API-Wordlist preview

API-Wordlist

GitHubnet-hunter121/api-wordlist

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

api-security-testingcurated-resourcesfuzzing+3
2545 years ago
PAYLOAD-LISTS preview

PAYLOAD-LISTS

GitHubnu11secur1ty/payload-lists

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

curated-resourceseducationpayload-generation+3
48 days ago
WAFEC preview

WAFEC

GitHubowasp/wafec

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

curated-resourceseducationlearning-paths-courses+3
12 years ago
DSpace__DSpace_CVE-2016-10726_4-4 preview

DSpace__DSpace_CVE-2016-10726_4-4

GitHubshoucheng3/dspace__dspace_cve-2016-10726_4-4

Repository containing the DSpace 4.4 source code with a focus on CVE-2016-10726, providing a reference for vulnerability analysis and educational…

code-analysiscurated-resourceseducation+2
1 year ago
xss-payload-list preview

xss-payload-list

GitHubh3x0v3rl0rd/xss-payload-list

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.

curated-resourceseducationvulnerability-analysis+2
5 years ago
tbhm preview

tbhm

GitHubjhaddix/tbhm

The Bug Hunters Methodology

curated-resourceseducationlearning-paths-courses+4
4.4k3 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubtankirat/cve-2017-5638

Educational analysis of Apache Struts 2 RCE vulnerability CVE-2017-5638, including exploit details, Equifax case study, and prevention measures.

curated-resourceseducationexploitation+3
4 years ago
Se7enSlip preview

Se7enSlip

GitHubshalevo13/se7enslip

A scanner and testter of the CVE-2025-11001 of 7-zip

curated-resourceseducationexploitation+3
410 months ago
Previous123Next