Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
proxychains preview

proxychains

GitHubhaad/proxychains

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…

dns-analysisnetwork-securitypenetration-testing+1
7.9k
2 years ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
88614 days ago
Empire-GUI preview

Empire-GUI

GitHubempireproject/empire-gui

Empire client application

command-and-controlpenetration-testing-frameworkspost-exploitation+2
5027 years ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubprojectzeroindia/cve-2019-19781

Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

command-and-controlexploitationpenetration-testing+3
3676 years ago
wePWNise preview

wePWNise

GitHubreverseclabs/wepwnise

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

exploit-frameworksids-ips-evasionpayload-development+5
3497 years ago
pFuzz preview

pFuzz

GitHubredsection/pfuzz

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

fuzzingpenetration-testingred-teaming+2
1615 years ago
DatajackProxy preview

DatajackProxy

GitHubnccgroup/datajackproxy

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

network-securitypenetration-testingred-teaming+2
1037 years ago
cc-ddos preview

cc-ddos

GitHubnayumidev/cc-ddos

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

penetration-testingred-teamingweb-application-exploitation
811 year ago
vbulletin-exploits preview

vbulletin-exploits

GitHubambionics/vbulletin-exploits

Exploits targeting vBulletin.

exploitationpenetration-testingred-teaming+1
753 years ago
frida-c2-mcp preview

frida-c2-mcp

GitHubs4dp4nd4/frida-c2-mcp

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

android-securitycommand-and-controldynamic-analysis-sandboxing+8
615 months ago
Burp-Encode-IP preview

Burp-Encode-IP

GitHube1abrador/burp-encode-ip

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

dns-fuzzingpenetration-testingred-teaming+2
482 years ago
carina preview

carina

GitHubcodelatteid/carina

Webshell, Virtual Private Server (VPS) and cPanel Database

command-and-controldatabase-securitypenetration-testing+1
383 years ago
Anvil preview

Anvil

GitHubshellkraft/anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

binary-analysisexploitationpenetration-testing+5
375 months ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker
api-security-testingids-ips-evasioninformation-gathering+6
332 days ago
hideNsneak preview

hideNsneak

GitHubrmikehodges/hidensneak

a CLI for ephemeral penetration testing

cloud-securitycommand-and-controlpayload-generation+5
176 years ago
CVE-2019-18935 preview

CVE-2019-18935

GitHubmurataydemir/cve-2019-18935

[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization

exploitationpayload-developmentpenetration-testing+3
165 years ago
ToolShell preview

ToolShell

GitHubl0ggg/toolshell

Exploit for ToolShell

exploitationpenetration-testingred-teaming+1
159 months ago
CVE-2025-64446-FortiWeb-CGI-Bypass-PoC preview

CVE-2025-64446-FortiWeb-CGI-Bypass-PoC

GitHubsxyrxyy/cve-2025-64446-fortiweb-cgi-bypass-poc
exploitationpenetration-testingred-teaming+3
139 months ago
Previous123Next