Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
99 results
SSRF-Testing preview

SSRF-Testing

GitHubcujanovic/ssrf-testing

SSRF (Server Side Request Forgery) testing resources

cloud-securitycurated-resourceseducation+6
2.5k
1 year ago
blind-ssrf-chains preview

blind-ssrf-chains

GitHubassetnote/blind-ssrf-chains

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

cloud-securitycurated-resourceseducation+5
9864 years ago
cve-2026-22874-gitea-ssrf-allowlist preview

cve-2026-22874-gitea-ssrf-allowlist

GitHubm8seven/cve-2026-22874-gitea-ssrf-allowlist

CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.

cloud-securitycurated-resourceseducation+3
21 month ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

cloud-securityctfcurated-resources+9
27.0k29 days ago
Learn-Web-Hacking preview

Learn-Web-Hacking

GitHublylemi/learn-web-hacking

Structured study notes covering web hacking fundamentals, common vulnerabilities, penetration testing techniques, and defensive security, with…

curated-resourceseducationlearning-paths-courses+2
5.5k2 days ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

container-escapectfcurated-resources+9
6 days ago
fuzzdb preview

fuzzdb

GitHubfuzzdb-project/fuzzdb

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

curated-resourcesfuzzinginformation-gathering+3
9.0k6 years ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k5 months ago
Claude-BugHunter preview

Claude-BugHunter

GitHubelementalsouls/claude-bughunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

api-securitycloud-securitycurated-resources+8
3.8k1 day ago
Nuclei-Templates-Collection preview

Nuclei-Templates-Collection

GitHubemadshanab/nuclei-templates-collection

Nuclei Templates Collection

api-securitycurated-resourcesfuzzing+6
1.2k8 months ago
shellshocker-pocs preview

shellshocker-pocs

GitHubmubix/shellshocker-pocs

Collection of Proof of Concepts and Potential Targets for #ShellShocker

curated-resourcesexploitationpenetration-testing+3
8896 years ago
security-labs-pocs preview

security-labs-pocs

GitHubdatadog/security-labs-pocs

Proof of concept code for Datadog Security Labs referenced exploits.

container-escapecurated-resourcesexploitation+4
4492 days ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
5464 years ago
awesome-websocket-security preview

awesome-websocket-security

GitHubpalindromelabs/awesome-websocket-security

Awesome information for WebSockets security research

curated-resourcesfuzzinglabs-practice+4
3134 years ago
Oneliner-Bugbounty preview

Oneliner-Bugbounty

GitHubdaffainfo/oneliner-bugbounty

A collection oneliner scripts for bug bounty

crawlercurated-resourcesinformation-gathering+6
1852 years ago
wordpress-exploits preview

wordpress-exploits

GitHubrandomrobbiebf/wordpress-exploits

Random Wordpres Exploits May or May Not Work.

curated-resourcesexploitationpenetration-testing+3
35 years ago
Bug_Bounty_writeups preview

Bug_Bounty_writeups

GitHubalexbieber/bug_bounty_writeups

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

curated-resourceseducationvulnerability-analysis+1
8524 years ago
CVE-2026-50131 preview

CVE-2026-50131

GitHubchaitanyagarware/cve-2026-50131

CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page

curated-resourceseducationinformation-gathering+3
11 month ago
Previous123456Next