Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
skipfish preview

skipfish

GitHubspinkham/skipfish

Web application security scanner created by lcamtuf for google - Unofficial Mirror

crawlerdynamic-analysis-sandboxingfuzzing+7
878
13 years ago
BurpCrypto preview

BurpCrypto

GitHubwhwlsfb/burpcrypto

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

encryption-decryption-toolsfuzzingpayload-generation+1
1.6k3 years ago
NucleiFuzzer preview

NucleiFuzzer

GitHub0xkayala/nucleifuzzer

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

fuzzinginformation-gatheringpenetration-testing+3
1.9k4 months ago
htcap preview

htcap

GitHubfcavallarin/htcap

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

crawlerfuzzingpenetration-testing+2
6284 years ago
xsscrapy preview

xsscrapy

GitHubdanmcinerney/xsscrapy

XSS spider - 66/66 wavsep XSS detected

fuzzingvulnerability-analysisweb-security+1
1.7k4 years ago
xsssniper preview

xsssniper

GitHubgbrindisi/xsssniper

An automatic XSS discovery tool

fuzzingvulnerability-analysisweb-security+1
4238 years ago
WAF-A-MoLE preview

WAF-A-MoLE

GitHubavalz/waf-a-mole

A guided mutation-based fuzzer for ML-based Web Application Firewalls

adversarial-attackfuzzingmachine-learning+2
2052 years ago
api_wordlist preview

api_wordlist

GitHubchrislockard/api_wordlist

A wordlist of API names for web application assessments

api-security-testingcurated-resourcesfuzzing+2
9321 year ago
goWAPT preview

goWAPT

GitHubdzonerzy/gowapt

Go Web Application Penetration Test

fuzzingpenetration-testingscripting-automation+4
3452 years ago
pFuzz preview

pFuzz

GitHubredsection/pfuzz

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

fuzzingpenetration-testingred-teaming+2
1615 years ago
API-Wordlist preview

API-Wordlist

GitHubnet-hunter121/api-wordlist

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

api-security-testingcurated-resourcesfuzzing+3
2555 years ago
CVE-2024-5124 preview

CVE-2024-5124

GitHubgogo2464/cve-2024-5124

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

cryptographyexploitationfuzzing+3
11 year ago
fuzzdb preview

fuzzdb

GitHubfuzzdb-project/fuzzdb

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

curated-resourcesdns-fuzzingfuzzing+4
9.0k6 years ago
TInjA preview

TInjA

GitHubhackmanit/tinja

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

dynamic-code-analysisfuzzingpenetration-testing+3
4274 months ago
ci_fuzz preview

ci_fuzz

GitHubmvdevnull/ci_fuzz

Command Injection Web Fuzzer Script for mitmproxy

fuzzingpenetration-testingvulnerability-analysis+1
48 years ago
CVE-2019-5096-GoAhead-Web-Server-Dos-Exploit preview

CVE-2019-5096-GoAhead-Web-Server-Dos-Exploit

GitHubianxtianxt/cve-2019-5096-goahead-web-server-dos-exploit

Python exploit for CVE-2019-5096, a use-after-free vulnerability in GoAhead web server's upload handler, causing denial of service via double-free.

binary-exploitationexploitationfuzzing+2
16 years ago
Angora preview

Angora

GitHubangorafuzzer/angora

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…

dynamic-code-analysisfuzzingvulnerability-analysis
9574 years ago
jdam preview

jdam

GitLabmichenriksen/jdam

A structure-aware JSON fuzzer

fuzzingpenetration-testingvulnerability-analysis+1
555 years ago
Previous123Next