Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
toolbox preview

toolbox

GitHubgo-appsec/toolbox

Collaborative application security testing between humans and agents via CLI and MCP

api-security-testingcrawlerdynamic-analysis-sandboxing+8
41
3 days ago
nfcgate preview

nfcgate

GitHubnfcgate/nfcgate

An NFC research toolkit application for Android

android-securityeducationexploitation+5
2.3k1 month ago
web-penetration-drupal preview

web-penetration-drupal

GitHuberman-bolukbasi/web-penetration-drupal

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

exploit-frameworkspenetration-testingreconnaissance+3
1 month ago
network-security-lab preview

network-security-lab

GitHubamirmuhammadmarvi/network-security-lab

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2

configuration-auditingeducationexploitation+7
2 months ago
Pegasus-Pentest-Arsenal preview

Pegasus-Pentest-Arsenal

GitHubsobri3195/pegasus-pentest-arsenal

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

api-security-testingctfeducation+9
554 months ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5535 months ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
105 months ago
Anvil preview

Anvil

GitHubshellkraft/anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

binary-analysisexploitationpenetration-testing+5
375 months ago
htb-ctf-walkthroughs preview

htb-ctf-walkthroughs

GitLabrootsecnz/htb-ctf-walkthroughs

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

ctfeducationexploitation+6
5 months ago
debugHunter preview

debugHunter

GitHubdevploit/debughunter

Discover hidden debugging parameters and uncover web application secrets

ctfinformation-gatheringpenetration-testing+3
2486 months ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1197 months ago
NextRce preview

NextRce

GitHubynsmroztas/nextrce

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

command-and-controlexploitationpayload-development+5
2568 months ago
cve-2023-28771-demo preview
Archived

cve-2023-28771-demo

GitHubjinparkmida/cve-2023-28771-demo
exploitationpenetration-testingreconnaissance+2
1 year ago
TIDoS-Framework preview

TIDoS-Framework

GitHub0xinfection/tidos-framework

The Offensive Manual Web Application Penetration Testing Framework.

exploitationfuzzinginformation-gathering+7
1.9k5 years ago
domain-to-webapp preview

domain-to-webapp

GitHubcyberblackhole/domain-to-webapp

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

information-gatheringpenetration-testingreconnaissance+2
57 years ago
ReconCat preview

ReconCat

GitHubdaudmalik06/reconcat

A small Php application to fetch archive url snapshots from archive.org. using it you can fetch complete list of snapshot urls of any year or…

information-gatheringosintpenetration-testing+2
788 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubpayatu/cve-2017-5638

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

command-and-controlexploitationpenetration-testing+3
89 years ago
clusterd preview

clusterd

GitHubhatriot/clusterd

application server attack toolkit

exploit-frameworkspayload-generationpenetration-testing+3
68710 years ago