Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
69 results
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
echteeteepee preview

echteeteepee

GitHubperplext/echteeteepee

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

dynamic-analysis-sandboxingeducationfuzzing+3
51 year ago
turbo-intruder preview

turbo-intruder

GitHubportswigger/turbo-intruder

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

fuzzingpenetration-testingvulnerability-analysis+1
1.8k10 days ago
monsoon preview

monsoon

GitHubredteampentesting/monsoon

Fast HTTP enumerator

fuzzinginformation-gatheringpenetration-testing+1
5001 month ago
ViteVulScan preview

ViteVulScan

GitHubjackieya/vitevulscan

针对CVE-2025-30208和CVE-2025-31125的漏洞利用

exploitationfuzzinginformation-gathering+3
71 year ago
gosentry preview

gosentry

GitHubtrailofbits/gosentry

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

binary-analysiscode-analysisdevsecops+5
11712 days ago
CVE-2024-35333 preview

CVE-2024-35333

GitHubmomo1239/cve-2024-35333
binary-exploitationeducationexploitation+3
2 years ago
goWAPT preview

goWAPT

GitHubdzonerzy/gowapt

Go Web Application Penetration Test

fuzzingpenetration-testingscripting-automation+4
3471 year ago
golang-CVE-2023-44487 preview

golang-CVE-2023-44487

GitHubretocode/golang-cve-2023-44487
exploitationfuzzingpenetration-testing+2
22 years ago
smugglefuzz preview

smugglefuzz

GitHubmoopinger/smugglefuzz

A rapid HTTP downgrade smuggling scanner written in Go.

api-security-testingfuzzingpenetration-testing+3
3122 years ago
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

fuzzinginformation-gatheringpenetration-testing+2
16.5k1 month ago
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.2k6 days ago
HackVault preview

HackVault

GitHub0xsobky/hackvault

A container repository for my public web hacks!

fuzzingpenetration-testingreconnaissance+1
2.0k7 years ago
wtf preview

wtf

GitHub0vercl0k/wtf

Distributed, code-coverage guided snapshot-based fuzzer for user and kernel-mode targets on Windows and Linux, with emulator and hypervisor backends.

binary-analysisdynamic-analysis-sandboxingexploitation+2
1.8k7h 5m ago
leaky-paths preview

leaky-paths

GitHubayoubfathi/leaky-paths

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…

curated-resourcesfuzzinginformation-gathering+3
1.2k4 months ago
regexploit preview

regexploit

GitHubdoyensec/regexploit

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

fuzzingstatic-code-analysisvulnerability-analysis
8482 years ago
WS-Attacker preview

WS-Attacker

GitHubrub-nds/ws-attacker

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University…

fuzzingpenetration-testingvulnerability-analysis+1
4954 years ago
bluebox preview

bluebox

GitHubjesusprubio/bluebox

A collection of exploits for different VoIP products.

exploitationexploit-frameworksfuzzing+5
2641 year ago
Previous1234Next