Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
SafeLine preview

SafeLine

GitHubchaitin/safeline

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

anti-botapi-securityapi-security-testing+8
22.7k
4 days ago
Hollow preview

Hollow

GitHubchaelsoo/hollow

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

binary-exploitationencryption-decryption-toolsexploitation+7
1022 months ago
mhr-cfw preview

mhr-cfw

GitHubdenuitt1/mhr-cfw

A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

cloud-securityids-ips-evasionred-teaming+1
4.4k4 months ago
IPRotate_Burp_Extension preview

IPRotate_Burp_Extension

GitHubrhinosecuritylabs/iprotate_burp_extension

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

cloud-securityids-ips-evasionpenetration-testing+2
8957 months ago
xencrypt preview

xencrypt

GitHubthe-xentropy/xencrypt

A PowerShell script anti-virus evasion tool

exploitationids-ips-evasionpayload-generation+2
1.2k6 years ago
PwnSTAR preview

PwnSTAR

GitHubsilverfoxx/pwnstar

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

captcha-bypassdns-analysisexploitation+7
26112 years ago
trojanizer preview

trojanizer

GitHubr00t-3xp10it/trojanizer

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros

command-and-controlexploitationids-ips-evasion+6
2948 years ago
Malcolm preview

Malcolm

GitHubcisagov/malcolm

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

digital-forensicsdns-analysisforensics+9
2.5k1 month ago
duckhunt preview

duckhunt

GitHubpmsosa/duckhunt

:dart: Prevent RubberDucky (or other keystroke injection) attacks

defensive-toolshardware-securityids-ips-evasion
5426 years ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
353 days ago
al-khaser preview

al-khaser

GitHubayoubfaouzi/al-khaser

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

educationids-ips-evasionlabs-practice+3
7.1k2 months ago
wificurse preview
Archived

wificurse

GitHuboblique/wificurse

WiFi Jamming tool

educationids-ips-evasionpenetration-testing+2
10412 years ago
InfraGuard preview

InfraGuard

GitHubwhispergate/infraguard

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

anti-botcommand-and-controldns-analysis+8
3201 month ago
yolo-cage preview
Archived

yolo-cage

GitHubborenstein/yolo-cage

AI coding agents that can't exfiltrate secrets or merge their own PRs.

ai-securitycloud-securitycontainer-security+7
1097 months ago
BounceBack preview

BounceBack

GitHubd00movenok/bounceback

↕️🤫 Stealth redirector for your red team operation security

command-and-controlids-ips-evasionpenetration-testing+3
1.1k2 months ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.1k12h 57m ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5576 months ago
CallMeWin32kDriver preview

CallMeWin32kDriver

GitHubgmh5225/callmewin32kdriver

Load your driver like win32k.sys

adversarial-attackids-ips-evasionpost-exploitation+1
2584 years ago
Previous123Next