Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
69 results
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

api-security-testingcrawlerdevsecops+8
12
12 days ago
ApiHunter preview

ApiHunter

GitHubteycir/apihunter

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

api-securitydevsecopsdynamic-analysis-sandboxing+6
252 months ago
ore-mal-pkg-inspector preview

ore-mal-pkg-inspector

GitHubrapticore/ore-mal-pkg-inspector

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

code-analysisdevsecopseducation+6
84 months ago
Sirius preview

Sirius

GitHubsiriusscan/sirius

Open-source vulnerability scanner with automated network discovery, CVE-based detection, CVSS scoring, risk dashboards, remote agents via gRPC, and a…

api-securitycloud-securitycontainer-security+6
1.7k27 days ago
ChopChop preview

ChopChop

GitHubmichelin/chopchop

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

configuration-auditingdevsecopsinformation-gathering+2
7125 years ago
osmedeus preview

osmedeus

GitHubj3ssie/osmedeus

A Modern Orchestration Engine for Security

cloud-securitydevsecopsinformation-gathering+5
6.6k2 days ago
cve-mcp-server preview

cve-mcp-server

GitHubmukul975/cve-mcp-server

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

api-securitydevsecopsincident-response+6
1.6k2 months ago
oxo preview

oxo

GitHubostorlab/oxo

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

devsecopsmobile-securitynetwork-security+3
5822h 40m ago
directus-security preview

directus-security

GitHubperufitlife/directus-security

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

api-security-testingcrawlerdevsecops+6
2 months ago
hephaestus-server-forger preview

hephaestus-server-forger

GitHubrodhnin/hephaestus-server-forger

server security auditor scanning Apache, Nginx, and IIS configurations with AI-powered hardening guides and professional reporting.

ai-securitycloud-securityconfiguration-auditing+4
14 months ago
faraday preview

faraday

GitHubinfobyte/faraday

Open Source Vulnerability Management Platform

api-securitydevsecopspenetration-testing+1
6.7k10 days ago
bumblebee preview

bumblebee

GitHubperplexityai/bumblebee

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

devsecopsincident-responseinformation-gathering+3
5.0k1 month ago
Dark-Moon preview

Dark-Moon

GitHubascit31/dark-moon

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

ai-securitycloud-securitydevsecops+6
9326 days ago
ElectricEye preview

ElectricEye

GitHubjonrau1/electriceye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

cloud-securityconfiguration-auditingdevsecops+5
1.0k1 year ago
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
7804 months ago
apex preview

apex

GitHubpensarai/apex

AI-powered offensive security testing using autonomous agents, directly in your terminal.

ai-securitycloud-securitydevsecops+7
3075 days ago
kubebot preview

kubebot

GitHubanshumanbh/kubebot

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

cloud-securitydevsecopsinformation-gathering+5
1642 years ago
studio preview

studio

GitHubshipsecai/studio

Workflow automation for Security Teams

cloud-securitydevsecopseducation+7
3796 months ago
Previous1234Next