Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
katana preview

katana

GitHubprojectdiscovery/katana

A next-generation crawling and spidering framework.

api-securityapi-security-testingcrawler+7
17.5k
10 days ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.1k16 days ago
Agentic-Bug-Hunter preview

Agentic-Bug-Hunter

GitHubawarexone/agentic-bug-hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

ai-securityapi-security-testingcloud-security+8
5.1k2 days ago
kiterunner preview

kiterunner

GitHubassetnote/kiterunner

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

api-securityapi-security-testingdynamic-code-analysis+5
3.3k5 years ago
chaos-client preview

chaos-client

GitHubprojectdiscovery/chaos-client

Go client to communicate with Chaos DB API.

api-security-testingdns-subdomain-enumerationinformation-gathering+2
88414 days ago
wpprobe preview

wpprobe

GitHubchocapikk/wpprobe

A fast WordPress plugin enumeration tool

api-security-testingcrawlerexploitation+5
95127 days ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5576 months ago
x8-Burp preview

x8-Burp

GitHubimpact-i/x8-burp

Hidden parameters discovery suite

api-security-testinginformation-gatheringreconnaissance+2
2253 years ago
ferret preview

ferret

GitHubsynlace/ferret

The collaborative web app pentest suite

ai-securityapi-security-testingdynamic-analysis-sandboxing+6
572 months ago
Pegasus-Pentest-Arsenal preview

Pegasus-Pentest-Arsenal

GitHubsobri3195/pegasus-pentest-arsenal

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

api-security-testingctfeducation+9
575 months ago
bug-reaper preview

bug-reaper

GitHubshaniidev/bug-reaper

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

api-security-testingctfeducation+8
727 months ago
wpx preview

wpx

GitHubgreg-randall/wpx

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

api-security-testingcrawlerinformation-gathering+6
105 months ago
reconix preview

reconix

GitHubaquibpro/reconix

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

api-security-testingcrawlerexploitation+8
25 months ago
CVE-2025-51867 preview

CVE-2025-51867

GitHubsecsys-fdu/cve-2025-51867

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

api-security-testinginformation-gatheringpenetration-testing+3
1 year ago
RISE-Ultimate_Project_Manager_e_CRM preview

RISE-Ultimate_Project_Manager_e_CRM

GitHubl4zyfox/rise-ultimate_project_manager_e_crm

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

api-security-testinginformation-gatheringpenetration-testing+3
1 year ago
Previous123Next