Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
69 results
flareprox preview

flareprox

GitHubmrturvey/flareprox

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

api-security-testinginformation-gatheringpenetration-testing+5
797
10 months ago
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k1 day ago
SDK preview

SDK

GitHubintelligencex/sdk

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

api-security-testinginformation-gatheringosint+2
5523 months ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
chaos-client preview

chaos-client

GitHubprojectdiscovery/chaos-client

Go client to communicate with Chaos DB API.

api-security-testingdns-subdomain-enumerationinformation-gathering+2
88414 days ago
GraphQLGrapper preview

GraphQLGrapper

GitHubm19o/graphqlgrapper

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

api-security-testinginformation-gatheringpenetration-testing+3
211 year ago
Burp_Collector preview

Burp_Collector

GitHubsajibuu/burp_collector

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

api-security-testinginformation-gatheringpenetration-testing+4
102 years ago
Arisu preview

Arisu

GitHubrazureink/arisu

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

api-security-testingcrawlerinformation-gathering+2
9 days ago
abdal-cve-2026-63030 preview

abdal-cve-2026-63030

GitHubebrasha/abdal-cve-2026-63030

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

api-security-testinginformation-gatheringpenetration-testing+2
31 month ago
CVE-2025-53640 preview

CVE-2025-53640

GitHubrafaelcorvino1/cve-2025-53640

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

api-security-testinginformation-gatheringosint+3
18 months ago
CVE-2026-26012 preview

CVE-2026-26012

GitHubdiegobaelen/cve-2026-26012

Proof-of-concept exploit for CVE-2026-26012, demonstrating an authenticated organization collection permissions bypass and cipher enumeration in…

api-security-testingexploitationinformation-gathering+3
7 months ago
CVE-2025-61148 preview

CVE-2025-61148

GitHubsharma19d/cve-2025-61148

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

api-security-testingeducationinformation-gathering+3
9 months ago
CVE-2025-51867 preview

CVE-2025-51867

GitHubsecsys-fdu/cve-2025-51867

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

api-security-testinginformation-gatheringpenetration-testing+3
1 year ago
CVE-2024-50633 preview

CVE-2024-50633

GitHubcetinpy/cve-2024-50633

Proof-of-concept exploit for CVE-2024-50633, a Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9–v3.3.2, enabling unauthorized…

api-security-testingexploitationinformation-gathering+3
1 year ago
CVE-2023-6289 preview

CVE-2023-6289

GitHubrandomrobbiebf/cve-2023-6289

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

api-security-testingexploitationinformation-gathering+3
2 years ago
selenium-wire preview
Archived

selenium-wire

GitHubwkeeling/selenium-wire

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

api-security-testinginformation-gatheringpenetration-testing+2
2.0k2 years ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5576 months ago
WSSAT preview

WSSAT

GitHubyalcinyolalan/wssat

WEB SERVICE SECURITY ASSESSMENT TOOL

api-security-testingdynamic-analysis-sandboxinginformation-gathering+3
3884 years ago
Previous1234Next