Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
246 results
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
1113 days ago
ParaForge preview

ParaForge

GitHubanof-cyber/paraforge

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

fuzzinginformation-gatheringpenetration-testing+1
1423 years ago
s3dns preview

s3dns

GitHubolizimmermann/s3dns

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

cloud-securitydns-analysisinformation-gathering+5
1283h 33m ago
BLE-Replay preview

BLE-Replay

GitHubnccgroup/ble-replay

BLE-Replay is a Bluetooth Low Energy (BLE) peripheral assessment tool

bluetooth-securityfuzzinghardware-iot-security+3
15210 years ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
2579 months ago
Eagle preview

Eagle

GitHubbitthebyte/eagle

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

exploitationinformation-gatheringmisconfiguration+4
1295 years ago
evine preview

evine

GitHubsaeeddhqan/evine

Interactive CLI Web Crawler

crawlerinformation-gatheringosint+2
1813 months ago
Combined-Wordlists preview

Combined-Wordlists

GitHub0xspade/combined-wordlists

A combined wordlists for files and directory discovery

curated-resourcesinformation-gatheringpenetration-testing+2
1325 years ago
wordlistgen preview

wordlistgen

GitHubethicalhackingplayground/wordlistgen

Generates target specific word lists for Fuzzing with fuff

fuzzinginformation-gatheringpayload-generation+1
1136 years ago
smod preview

smod

GitHub0x0mar/smod

MODBUS Penetration Testing Framework

fuzzinginformation-gatheringnetwork-security+3
9510 years ago
ffufPostprocessing preview

ffufPostprocessing

GitHubdsecuredcom/ffufpostprocessing

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

fuzzinginformation-gatheringpenetration-testing+3
1442 years ago
ffufw preview

ffufw

GitHubpuzzlepeaches/ffufw

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

fuzzinginformation-gatheringpenetration-testing+2
1476 months ago
mkpath preview

mkpath

GitHubtrickest/mkpath

Make URL path combinations using a wordlist

fuzzinginformation-gatheringpenetration-testing+2
1743 years ago
web3-decoder preview

web3-decoder

GitHubnccgroup/web3-decoder

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

api-securityinformation-gatheringpenetration-testing+3
1173 months ago
Gemini-api-key-hunter preview

Gemini-api-key-hunter

GitHubcoffinxp/gemini-api-key-hunter

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

api-securitycloud-securityinformation-gathering+5
732 months ago
memscan preview

memscan

GitHubnccgroup/memscan

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

data-exfiltrationfuzzinginformation-gathering+5
1285 years ago
recon preview

recon

GitHubknowledge-wisdom-understanding/recon

Enumerate a target Based off of Nmap Results

ctfdns-analysisdns-subdomain-enumeration+9
762 years ago
Politician preview

Politician

GitHub0ldev/politician

Modern WiFi auditing library for ESP32 using advanced 802.11 techniques. Captures WPA/WPA2/WPA3 handshakes via PMKID extraction and CSA injection…

embedded-systems-securityfuzzinghardware-security+6
971 month ago
Previous1…789…14Next