Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
graphql-cop preview

graphql-cop

GitHubdolevf/graphql-cop

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

api-securityapi-security-testingdynamic-code-analysis+5
688
10 months ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.5k4 months ago
gf preview

gf

GitHubtomnomnom/gf

A wrapper around grep, to help you grep for things

code-analysisdynamic-code-analysisgeneral-purpose-utilities+7
2.1k2 years ago
Angora preview

Angora

GitHubangorafuzzer/angora

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

dynamic-code-analysisfuzzingvulnerability-analysis
9574 years ago
DLLirant preview

DLLirant

GitHubredteamsocietegenerale/dllirant

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

binary-analysisdynamic-code-analysisexploitation+3
5033 years ago
Elite preview

Elite

GitHubcobbr/elite

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

command-and-controldynamic-code-analysisencryption-decryption-tools+6
1217 years ago
BurpSentinel preview

BurpSentinel

GitHubdobin/burpsentinel

GUI Burp Plugin to ease discovering of security holes in web applications

dynamic-code-analysispenetration-testingvulnerability-analysis+3
1539 years ago
lightkeeper preview

lightkeeper

GitHubworksbutnottested/lightkeeper

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

binary-analysiscode-analysisdynamic-code-analysis+1
752 months ago
Winstrument preview

Winstrument

GitHubnccgroup/winstrument

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

binary-analysisdynamic-code-analysisreverse-engineering+1
686 years ago
centipede preview

centipede

GitHubdvyukov/centipede

Distributed coverage-guided fuzzing engine compatible with libFuzzer targets; scales to thousands of concurrent jobs, uses sanitizers and corpus…

dynamic-code-analysisfuzzingvulnerability-analysis
791 year ago
ExportHider preview

ExportHider

GitHubfrkngksl/exporthider

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

binary-analysisdynamic-code-analysisexploitation+4
334 months ago
ICSFuzz preview

ICSFuzz

GitHubmomalab/icsfuzz

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

dynamic-code-analysisembedded-systems-securityfuzzing+3
304 years ago
ghidra_stack_strings preview

ghidra_stack_strings

GitHubzxgio/ghidra_stack_strings

A script to detect stack-strings by using emulation (leveraging Unicorn)

binary-analysisdynamic-code-analysismalware-analysis+1
359 months ago
28458 preview

28458

GitHubraka200juta/28458

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

dynamic-code-analysisexploitationpenetration-testing+2
19 months ago
umberto preview
Archived

umberto

GitHubtrailofbits/umberto

Library and CLI for mutating structured data (JSON, XML, X.509) to support grammar-based fuzzing, with multiple mutation strategies and integration…

dynamic-code-analysisfuzzinggeneral-purpose-utilities+1
316 years ago
MobileApp-Pentest-Cheatsheet preview

MobileApp-Pentest-Cheatsheet

GitHubtanprathan/mobileapp-pentest-cheatsheet

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

android-securitycurated-resourcesdynamic-code-analysis+9
5.3k2 years ago
frida-scripts preview

frida-scripts

GitHub0xdea/frida-scripts

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

android-securitybinary-analysisdynamic-code-analysis+3
1.7k1 month ago
AndBug preview

AndBug

GitHubswdunlop/andbug

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…

android-securitydebuggersdynamic-code-analysis+2
59911 years ago
Previous12345Next