Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
86 results
bambdas preview

bambdas

GitHubportswigger/bambdas

Bambdas collection for Burp Suite Professional and Community.

curated-resourceseducationscripting-automation+3
530
2 months ago
SILENTCHAIN preview

SILENTCHAIN

GitHubsilentchainai/silentchain

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

ai-securityapi-security-testingcode-analysis+8
3731 month ago
BSCP-EXAM-GUIDE-BY-N3OARI-2026 preview

BSCP-EXAM-GUIDE-BY-N3OARI-2026

GitHubn3oari/bscp-exam-guide-by-n3oari-2026

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

curated-resourceseducationlabs-practice+3
2812 days ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
nextjs-middleware-auth-bypass-lab preview

nextjs-middleware-auth-bypass-lab

GitHubberraesen/nextjs-middleware-auth-bypass-lab

Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

authentication-authorizationeducationlabs-practice+3
120 days ago
Popcorn-TJNULL-OSCP- preview

Popcorn-TJNULL-OSCP-

GitHubr3fr4kt/popcorn-tjnull-oscp-

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

ctfeducationexploitation+7
2 months ago
CVE-Vulnerability-Research-Exploit-Analysis preview

CVE-Vulnerability-Research-Exploit-Analysis

GitHubadk86/cve-vulnerability-research-exploit-analysis

Researched and executed real-world CVE exploits in a controlled sandbox: CVE-2000-0168 DoS on Windows 95, ARP Spoofing with NTLMv2 credential…

educationexploitationnetwork-security+3
5 months ago
CVE-2014-6271-Shellshock- preview

CVE-2014-6271-Shellshock-

GitHubdrhaitham/cve-2014-6271-shellshock-

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

command-and-controlctfeducation+8
8 months ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

command-and-controleducationexploitation+7
8 months ago
web-threat-mitigation preview

web-threat-mitigation

GitHubbrunoh6/web-threat-mitigation

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

configuration-auditingdevsecopseducation+8
1 year ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k5 months ago
Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes preview

Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes

GitHubxalgord/massive-web-application-penetration-testing-bug-bounty-notes

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

curated-resourceseducationlearning-paths-courses+3
1.8k11 months ago
awesome-android-security preview

awesome-android-security

GitHubsaeidshirazi/awesome-android-security

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

android-securitycurated-resourceseducation+6
2.0k1 month ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubupdatelap/cve-2025-55182

React2Shell Scanner

educationexploitationpenetration-testing+3
47 months ago
cve-2026-40072-ssrf-lab preview

cve-2026-40072-ssrf-lab

GitHubu1tr0nex/cve-2026-40072-ssrf-lab

Hands-on lab for CVE-2026-40072 — SSRF vulnerability in web3.py via CCIP Read (EIP-3668)

educationlabs-practicepenetration-testing+3
2 months ago
BurpWpsScan preview

BurpWpsScan

GitHubteycir/burpwpsscan

Burp extension for wordpress security scanning

api-security-testingeducationexploitation+5
115 months ago
Agent-Security-Regression-Harness preview

Agent-Security-Regression-Harness

GitHubowasp/agent-security-regression-harness

Executable security regression testing for agentic applications and MCP-integrated systems.

ai-securityapi-security-testingcode-analysis+4
4827 days ago
Previous12345Next