Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
82 results
Awesome-Fuzzing preview

Awesome-Fuzzing

GitHubsecfigo/awesome-fuzzing

A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for…

binary-analysiscurated-resourceseducation+6
5.9k
3 years ago
awesome-industrial-control-system-security preview

awesome-industrial-control-system-security

GitHubhslatman/awesome-industrial-control-system-security

A curated list of resources related to Industrial Control System (ICS) security.

curated-resourcesexploitationfuzzing+9
2.0k0 years ago
open-source-web-scanners preview

open-source-web-scanners

GitHubpsiinon/open-source-web-scanners

Curated list of open-source web security scanners, including general-purpose scanners, infrastructure scanners, and fuzzers, ordered by GitHub stars.

curated-resourceseducationfuzzing+3
1.6k1 year ago
fuzzing-templates preview
Archived

fuzzing-templates

GitHubprojectdiscovery/fuzzing-templates

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

api-securitycurated-resourcesfuzzing+4
1082 years ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerdynamic-code-analysisfuzzing+8
15.2k1 year ago
AFLplusplus preview

AFLplusplus

GitHubaflplusplus/aflplusplus

AFL++ is a state-of-the-art fuzzer, and #1 in benchmarks. It was originally based on AFL. Today it comes with qemu 5.1, collision-free coverage,…

binary-analysisdns-fuzzingdynamic-analysis-sandboxing+3
6.8k1 month ago
TEE-reversing preview

TEE-reversing

GitHubenovella/tee-reversing

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

android-securitybinary-analysiscurated-resources+9
1.0k9 months ago
umap2 preview

umap2

GitHubnccgroup/umap2

Umap2 is the second revision of NCC Group's python based USB host security assessment tool.

dynamic-analysis-sandboxingembedded-systems-securityfuzzing+4
2875 years ago
umap preview

umap

GitHubnccgroup/umap

The USB host security assessment tool

fuzzinghardware-securitypenetration-testing
29412 years ago
TInjA preview

TInjA

GitHubhackmanit/tinja

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

dynamic-code-analysisfuzzingpenetration-testing+3
4305 months ago
extended-ssrf-search preview

extended-ssrf-search

GitHubdamian89/extended-ssrf-search

Smart ssrf scanner using different methods like parameter brute forcing in post and get...

fuzzingpenetration-testingvulnerability-scanners+1
2745 years ago
ParamPamPam preview

ParamPamPam

GitHubbo0om/parampampam

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

fuzzinginformation-gatheringweb-security
2754 years ago
vaf preview

vaf

GitHubandreiverse/vaf

Multi-threaded web fuzzer for URL path, HTTP header, and POST data brute-forcing with proxy support, status code filtering, and reflexive content…

fuzzingpenetration-testingvulnerability-scanners+1
3184 years ago
CrackQL preview

CrackQL

GitHubnicholasaleks/crackql

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

api-security-testingfuzzingpassword-attacks+2
3533 years ago
WordListGen preview

WordListGen

GitHubfrizb/wordlistgen

Super Simple Python Word List Generator for Fuzzing and Brute Forcing in Python

fuzzingpassword-crackingpenetration-testing
567 years ago
bug-bounty-tools preview

bug-bounty-tools

GitHubrxerium/bug-bounty-tools

A BASH Script to automate the installation of the most popular bug bounty tools

dns-subdomain-enumerationfuzzinginformation-gathering+7
279 months ago
ReconHound preview

ReconHound

GitLabs_r_e_e_r_a_j/reconhound

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

fuzzinginformation-gatheringpenetration-testing+3
15 months ago
cve-2023-21987-poc preview

cve-2023-21987-poc

GitHubchunzhennn/cve-2023-21987-poc

Proof-of-concept exploit for Oracle VirtualBox VGA out-of-bounds read vulnerability, demonstrating address leaking from VirtualBox components on…

binary-exploitationexploitationfuzzing+3
11 year ago
Previous12345Next