Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
227 results
nodriver preview

nodriver

GitHubultrafunkamsterdam/nodriver

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

anti-botcaptcha-bypasscrawler+8
4.7k
3 months ago
Interlace preview

Interlace

GitHubcodingo/interlace

Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

penetration-testingreconnaissancescripting-automation+1
1.3k11 months ago
autopwn preview

autopwn

GitHubnccgroup/autopwn

Specify targets and run sets of tools against them

penetration-testingpenetration-testing-frameworksreconnaissance+2
3897 years ago
rayder preview

rayder

GitHubdevanshbatham/rayder

A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows

penetration-testingreconnaissancescripting-automation+1
3082 years ago
asadbg preview

asadbg

GitHubnccgroup/asadbg

asadbg is a framework of tools to aid in automating live debugging of Cisco ASA devices

binary-analysisdebuggersembedded-systems-security+5
804 years ago
ComfyEngine preview

ComfyEngine

GitHubkashithecomfy/comfyengine

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

binary-analysisdebuggersdynamic-code-analysis+5
628 months ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
105 months ago
BurpSuite-Grand-Master-Tools preview

BurpSuite-Grand-Master-Tools

GitHubnu11secur1ty/burpsuite-grand-master-tools

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

penetration-testingreconnaissancescripting-automation+3
29 months ago
SleuthQL preview

SleuthQL

GitHubianxtianxt/sleuthql

SleuthQL是基于python3所开发的一款,用于批量爬行站点可能存在sql的地址。并且可以配合burp+sqlmap进行批量注入。 对比sqlmap手动单线程一个一个注入点的去识别,方便了很多。

penetration-testingreconnaissancescripting-automation+4
166 years ago
ElectronVulnerableVersion preview

ElectronVulnerableVersion

GitHubgtgalaxi/electronvulnerableversion

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

binary-analysisinformation-gatheringreconnaissance+3
72 years ago
CVE-2020-3452-PoC preview

CVE-2020-3452-PoC

GitHubxdev05/cve-2020-3452-poc
exploitationpenetration-testingreconnaissance+3
26 years ago
CVE-2025-1974_IngressNightmare_PoC preview

CVE-2025-1974_IngressNightmare_PoC

GitHubabrewer251/cve-2025-1974_ingressnightmare_poc
exploitationpenetration-testingreconnaissance+3
1 year ago
ghidra preview

ghidra

GitHubnationalsecurityagency/ghidra

Ghidra is a software reverse engineering (SRE) framework

binary-analysisdebuggersdynamic-analysis-sandboxing+8
72.5k3 days ago
cloudflare-bypass-2026 preview

cloudflare-bypass-2026

GitHub1837620622/cloudflare-bypass-2026

Cloudflare Turnstile 绕过工具 | Cloudflare Bypass Tool based on SeleniumBase UC Mode | 支持 Mac/Windows/Linux

anti-botcaptcha-bypassfingerprint-spoofing+3
4181 month ago
chomp-scan preview

chomp-scan

GitHubsolomonsklash/chomp-scan

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

dns-analysisinformation-gatheringpenetration-testing+6
3946 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubgrupooruss/cve-2024-6387

regreSSHion vulnerability in OpenSSH CVE-2024-6387 Testing Script

configuration-auditingnetwork-securitypenetration-testing+3
22 years ago
LangAlpha preview

LangAlpha

GitHubginlix-ai/langalpha

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

crawlerdata-exfiltrationinformation-gathering+6
1.7k9h 40m ago
Cortex preview

Cortex

GitHubthehive-project/cortex

Cortex: a Powerful Observable Analysis and Active Response Engine

digital-forensicsincident-responseinformation-gathering+4
1.6k1 month ago
Previous1…456…13Next