Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
APIHarvester preview

APIHarvester

GitHubpiratesshield/apiharvester

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

api-securityapi-security-testingcrawler+9
32
2 months ago
akca preview

akca

GitHubakha-security/akca

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

api-security-testingdefensive-toolsdynamic-analysis-sandboxing+9
2225 days ago
SmartScanner-Source preview

SmartScanner-Source

GitHubfauxrougee/smartscanner-source

Web vulnerability scanner built with C++17 and Qt 6, featuring a GUI, CLI, configurable crawling, and JSON reports. Reconstructed for educational…

configuration-auditingcrawlereducation+7
122 days ago
KUMO-Domain-Recon-Tool preview

KUMO-Domain-Recon-Tool

GitHubkarim852/kumo-domain-recon-tool

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

dns-analysisinformation-gatheringosint+8
626 days ago
edu-recon preview

edu-recon

GitHubyeee3642/edu-recon

Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web…

educationexploitationinformation-gathering+8
1 month ago
Agentic-Bug-Hunter preview

Agentic-Bug-Hunter

GitHubawarexone/agentic-bug-hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

ai-securityapi-security-testingcloud-security+8
5.3k6 days ago
gf preview

gf

GitHubtomnomnom/gf

A wrapper around grep, to help you grep for things

code-analysisdynamic-code-analysisgeneral-purpose-utilities+7
2.1k6 years ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1829 days ago
One-Liner-Collections preview

One-Liner-Collections

GitHubcybertix-pvt-ltd/one-liner-collections

This Repositories contains list of One Liners with Descriptions and Installation requirements

curated-resourcesinformation-gatheringpenetration-testing+5
5091 year ago
Oneliner-Bugbounty preview

Oneliner-Bugbounty

GitHubdaffainfo/oneliner-bugbounty

A collection oneliner scripts for bug bounty

crawlercurated-resourcesinformation-gathering+6
1852 years ago
pwn_jenkins preview

pwn_jenkins

GitHubgquere/pwn_jenkins

Notes about attacking Jenkins servers

exploitationinformation-gatheringpassword-attacks+6
2.1k2 years ago
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

ai-securityapi-security-testingcloud-infrastructure-security+8
85522h 21m ago
CVE-2026-66066 preview

CVE-2026-66066

GitHubhackspeak/cve-2026-66066

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

exploitationinformation-gatheringpenetration-testing+5
42 months ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
54119 days ago
Shockwave-OSS preview

Shockwave-OSS

GitHubgal-nagli/shockwave-oss

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

curated-resourceseducationfuzzing+9
7502 years ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Appspec YML and YAML leaks

api-securitycloud-securityinformation-gathering+4
12 years ago
behat-config-leaks preview

behat-config-leaks

GitHubcappricio-securities/behat-config-leaks

BeHat Configuration file leaking

information-gatheringmisconfigurationsecret-detection+3
12 years ago
vigolium preview

vigolium

GitHubvigolium/vigolium

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

ai-securityapi-security-testingauthentication+9
1.1k6 days ago
Previous12Next