Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
nDPI preview

nDPI

GitHubntop/ndpi

Open Source Deep Packet Inspection Software Toolkit

dns-analysisfuzzingintrusion-detection+5
4.6k1 day ago
HawkScan preview

HawkScan

GitHubc0dejump/hawkscan

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

crawlerfuzzinginformation-gathering+5
4623 years ago
HackVault preview

HackVault

GitHub0xsobky/hackvault

A container repository for my public web hacks!

fuzzingpenetration-testingreconnaissance+1
2.0k8 years ago
rustbuster preview

rustbuster

GitHubphra/rustbuster

A Comprehensive Web Fuzzer and Content Discovery Tool

dns-subdomain-enumerationfuzzinginformation-gathering+2
5584 years ago
SourceWolf preview

SourceWolf

GitHubksharinarayanan/sourcewolf

Amazingly fast response crawler to find juicy stuff in the source code! 😎🔥

crawlerfuzzinginformation-gathering+3
1563 years ago
ShiroScan preview

ShiroScan

GitHubianxtianxt/shiroscan

shiro 1.2.47 反序列化

exploitationfuzzingpenetration-testing+3
206 years ago
nextjs-cve-2026-44578 preview

nextjs-cve-2026-44578

GitHublove07oj/nextjs-cve-2026-44578

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and…

cloud-securityexploitationfuzzing+3
84 months ago
CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC preview

CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC

GitHubabrewer251/cve-2024-38475_sonicboom_apache_url_traversal_poc

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

exploitationfuzzingpenetration-testing+3
1 year ago
CVE-2024-38475 preview

CVE-2024-38475

GitHubsyaifulandy/cve-2024-38475

CVE-2024-38475 Scanner using FFUF + Seclists

fuzzingpenetration-testingreconnaissance+2
1 year ago
Raccoon preview

Raccoon

GitHubevyatarmeged/raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning

dns-analysisfuzzinginformation-gathering+6
4.0k1 year ago
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1473 years ago
secator preview

secator

GitHubfreelabz/secator

secator - the pentester's swiss knife

dns-analysisexploit-frameworksfuzzing+8
1.3k9h 10m ago
GooFuzz preview

GooFuzz

GitHubm3n0sd0n4ld/goofuzz

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

dns-subdomain-enumerationfuzzinginformation-gathering+3
1.6k9 months ago
WordList preview

WordList

GitHubrix4uni/wordlist

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

dns-subdomain-enumerationfuzzinginformation-gathering+6
1553 months ago
mkpath preview

mkpath

GitHubtrickest/mkpath

Make URL path combinations using a wordlist

fuzzinginformation-gatheringpenetration-testing+2
1753 years ago
recon preview

recon

GitHubknowledge-wisdom-understanding/recon

Enumerate a target Based off of Nmap Results

ctfdns-analysisdns-subdomain-enumeration+9
762 years ago
TIDoS-Framework preview

TIDoS-Framework

GitHub0xinfection/tidos-framework

The Offensive Manual Web Application Penetration Testing Framework.

exploitationfuzzinginformation-gathering+7
1.9k5 years ago
Reconator preview

Reconator

GitHubgokulapap/reconator

Automated reconnaissance framework with 17+ modules for subdomain enumeration, directory brute-forcing, JS/link mining, WAF fingerprinting, and…

dns-subdomain-enumerationfuzzinginformation-gathering+6
4391 month ago
Previous123456Next