Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
super-secret-finder preview

super-secret-finder

GitHubrandomrobbiebf/super-secret-finder

Automated secret matching plugin for Burp Suite that detects exposed API keys, tokens, and credentials in HTTP requests and responses for security…

api-securityinformation-gatheringpenetration-testing+3
63 years ago
JSScanner preview

JSScanner

GitHubdark-warlord14/jsscanner

You can read the writeup on this script here

information-gatheringosintsecret-detection+1
2736 years ago
Gemini-api-key-hunter preview

Gemini-api-key-hunter

GitHubcoffinxp/gemini-api-key-hunter

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

api-securitycloud-securityinformation-gathering+5
641 month ago
AWS-Loot preview

AWS-Loot

GitHubsebastian-mora/aws-loot

Enumerates AWS environments for secrets by scanning EC2 userdata, Lambda environment variables and source code, and CodeBuild instances for…

cloud-securityinformation-gatheringpenetration-testing+1
656 years ago
CVE-2025-55183 preview

CVE-2025-55183

GitHubsaturate/cve-2025-55183

Scans web applications for React Server Actions source code exposure, extracting and detecting hardcoded secrets, API keys, and credentials.

exploitationinformation-gatheringsecret-detection+3
28 months ago
secret-regex-list preview

secret-regex-list

GitHubh33tlit/secret-regex-list

List of regex for scraping secret API keys and juicy information.

api-securitycloud-securityinformation-gathering+3
7304 years ago
POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability preview

POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability

GitHubsam00/poc-cve-2026-42826-2026-42826-microsoft-azure-devops-information-disclosure-vulnerability

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

cloud-securityexploitationinformation-gathering+4
22 days ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Scans web applications for exposed AWS AppSpec YAML files containing sensitive data like API keys and secrets, aiding bug bounty hunters and…

api-securitycloud-securityinformation-gathering+4
12 years ago
kubebot preview

kubebot

GitHubanshumanbh/kubebot

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

cloud-securitydevsecopsinformation-gathering+5
1641 year ago
pwn_jenkins preview

pwn_jenkins

GitHubgquere/pwn_jenkins

Exploit Jenkins instances via CVE-specific PoCs: RCE through Groovy scripts and deserialization, dump builds for cleartext secrets, password…

exploitationinformation-gatheringpassword-attacks+6
2.1k2 years ago
dora preview

dora

GitHubsdushantha/dora

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

information-gatheringpenetration-testingsecret-detection+1
3444 years ago
CVE-2023-27587-PoC preview

CVE-2023-27587-PoC

GitHubvagnerd/cve-2023-27587-poc

Proof-of-concept exploit for CVE-2023-27587, demonstrating Google Cloud API key leakage via error messages in a Rust web application. Includes…

api-securityexploitationinformation-gathering+3
53 years ago
behat-config-leaks preview

behat-config-leaks

GitHubcappricio-securities/behat-config-leaks

Automated vulnerability scanner that detects exposed BeHat configuration files and sends Telegram notifications. Ideal for bug bounty hunters and…

information-gatheringmisconfigurationsecret-detection+3
12 years ago
sccmsqlclient preview

sccmsqlclient

GitHubsynacktiv/sccmsqlclient

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

database-securityexploitationinformation-gathering+6
312 months ago
Jbin-website-secret-scraper preview

Jbin-website-secret-scraper

GitHubh33tlit/jbin-website-secret-scraper

Jbin will gather all the URLs from the website and then it will try to expose the secret data from them such as API keys, API secrets, API tokens and…

crawlerinformation-gatheringsecret-detection+1
1784 years ago
kenzer preview
Archived

kenzer

GitHubarpsyndicate/kenzer

automated web assets enumeration & scanning [DEPRECATED]

crawlerdns-analysisinformation-gathering+8
2883 years ago
SecretFinder preview

SecretFinder

GitHubm4ll0k/secretfinder

Regex-based scanner that discovers API keys, tokens, JWTs, and other secrets in JavaScript files, with support for URL extraction, custom regex, and…

information-gatheringosintsecret-detection+1
2.5k2 years ago
JSAnalyzer preview

JSAnalyzer

GitHubjenish-sojitra/jsanalyzer

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

api-securityemail-harvestinginformation-gathering+4
1.2k6 months ago
Previous1234Next