Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
137 results
TokenTactics preview

TokenTactics

GitHubrvrsh3ll/tokentactics

Azure JWT Token Manipulation Toolset

authenticationcloud-securitypenetration-testing+2
7371 year ago
SpringBreakPoC preview

SpringBreakPoC

GitHubfixyourface/springbreakpoc

PoC for SpringBreak (CVE-2017-8046)

exploitationpenetration-testingremote-access-tool+2
18 years ago
SiteCore-RCE-Detection preview

SiteCore-RCE-Detection

GitHubcrankyyash/sitecore-rce-detection

Python script to detect Sitecore Experience Platform pre-auth RCE (CVE-2021-42237) by probing vulnerable Report.ashx endpoints and analyzing HTTP…

exploitationpenetration-testingreconnaissance+2
3 years ago
insect preview

insect

GitHubnu11secur1ty/insect

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

fuzzinginformation-gatheringpenetration-testing+3
3 years ago
CVE-2026-44578-PoC preview

CVE-2026-44578-PoC

GitHubtocong282/cve-2026-44578-poc

Proof-of-concept exploit for CVE-2026-44578, a Server-Side Request Forgery in Next.js WebSocket upgrade handler. Includes detection mode and…

cloud-securityexploitationpenetration-testing+3
3 months ago
CVE-2023-32117 preview

CVE-2023-32117

GitHubrandomrobbiebf/cve-2023-32117

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

api-security-testingexploitationinformation-gathering+3
63 years ago
apkprobe preview

apkprobe

GitHubwadingporque/apkprobe

APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

android-securityinformation-gatheringmobile-security+5
49 months ago
JSONBee preview

JSONBee

GitHubzigoo0/jsonbee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

crawlerinformation-gatheringpenetration-testing+2
7672 years ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubcoldfusionx/cve-2022-36804

Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)

command-and-controlexploitationinformation-gathering+3
73 years ago
warf preview

warf

GitHubiamnihal/warf

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

information-gatheringosintpenetration-testing+3
1944 years ago
hakrawler preview

hakrawler

GitHubhakluke/hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

crawlerinformation-gatheringpenetration-testing+2
5.1k29 days ago
CVE-2026-47323 preview

CVE-2026-47323

GitHuboscerd/cve-2026-47323

Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE…

educationexploitationpenetration-testing+3
1 month ago
sj preview

sj

GitHubbishopfox/sj

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

api-security-testingpenetration-testingvulnerability-scanners+1
8759 days ago
AzSubEnum preview

AzSubEnum

GitHubyuyudhn/azsubenum

DNS-based subdomain enumeration tool for Azure services, probing App Services, Storage Accounts, Databases, Key Vaults, and CDN endpoints via…

cloud-securityinformation-gatheringpenetration-testing+2
812 years ago
CVE-2026-5029-Exploit preview

CVE-2026-5029-Exploit

GitHub0x00phantom-hat/cve-2026-5029-exploit

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

code-analysiseducationexploitation+3
1 month ago
noir preview

noir

GitHubowasp-noir/noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

api-securitydevsecopspenetration-testing+3
1.4k1 day ago
debugHunter preview

debugHunter

GitHubdevploit/debughunter

Discover hidden debugging parameters and uncover web application secrets

ctfinformation-gatheringpenetration-testing+3
2487 months ago
ParaForge preview

ParaForge

GitHubanof-cyber/paraforge

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

fuzzinginformation-gatheringpenetration-testing+1
1423 years ago
Previous12…8Next