Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
sharemylogin preview

sharemylogin

GitHubelandio-com/sharemylogin

Zero-Knowledge Credential Sharing

authenticationencryption-decryption-toolsprivacy+3
572 months ago
horusec preview

horusec

GitHubzupit/horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

cloud-securitycode-analysiscontainer-security+5
1.3k3 years ago
shotlooter preview

shotlooter

GitHubutkusen/shotlooter

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc

data-exfiltrationinformation-gatheringosint+2
6491 year ago
nord-stream preview

nord-stream

GitHubsynacktiv/nord-stream

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

data-exfiltrationdevsecopsexploitation+5
3772 months ago
SwaggerSpy preview

SwaggerSpy

GitHubundeadsec/swaggerspy

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

api-securityinformation-gatheringosint+1
3224 months ago
entropy preview

entropy

GitHubewenquim/entropy

CLI tool that scans codebases for high-entropy lines to detect potential secrets, with customizable file extension and top-N filtering.

code-analysissecret-detectionstatic-analysis
7354 months ago
jsubfinder preview

jsubfinder

GitHubthreatunknown/jsubfinder

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

information-gatheringosintreconnaissance+3
2841 year ago
gh-dork preview

gh-dork

GitHubmolly/gh-dork

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

information-gatheringosintreconnaissance+2
1374 years ago
deepsecrets preview

deepsecrets

GitHubavito-tech/deepsecrets

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

code-analysisdevsecopssecret-detection+1
1932 years ago
preflight preview

preflight

GitHubpreflightsh/preflight

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

code-analysisconfiguration-auditingdevsecops+8
6225 days ago
mhf preview

mhf

GitHubstuxctf/mhf

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

android-securityinformation-gatheringios-security+5
289 months ago
SecureAI-Scan preview

SecureAI-Scan

GitHubakanthed/secureai-scan

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

ai-securitycode-analysisdevsecops+5
2213 days ago
ci-supplychain-guard preview

ci-supplychain-guard

GitHubotsmane-ahmed/ci-supplychain-guard

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

code-analysiscontainer-securitydevsecops+5
287 months ago
kyubisweep preview

kyubisweep

GitHubtanmayshahane/kyubisweep

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

code-analysisconfiguration-auditingdevsecops+3
48 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
37 months ago
DiffCatcher preview

DiffCatcher

GitHubteycir/diffcatcher

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

code-analysisdevsecopsinformation-gathering+7
46 months ago
GitLeaks preview

GitLeaks

GitLabniclas-zone/ctr/gitleaks

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

code-analysiscontainer-securitydevsecops+1
2 months ago
GitLeaks preview

GitLeaks

GitLabniclas-zone/ci/gitleaks

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

code-analysisdevsecopssecret-detection+1
12 months ago
Previous123Next