Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
LEAKEY preview

LEAKEY

GitHubrynosec/leakey

Validates leaked API tokens and keys using customizable JSON-based signature checks. Designed for pentesters and bug hunters to determine the impact…

information-gatheringpenetration-testingsecret-detection+1
381
2 years ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
54015 days ago
GitLeaks preview

GitLeaks

GitLabniclas-zone/ctr/gitleaks

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

code-analysiscontainer-securitydevsecops+1
2 months ago
s3crets_scanner preview

s3crets_scanner

GitHubeilonh/s3crets_scanner

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

cloud-infrastructure-securitycloud-securitysecret-detection+1
5733 years ago
jsleak preview

jsleak

GitHubbyt3hx/jsleak

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

information-gatheringreconnaissancesecret-detection+1
5961 year ago
SwaggerSpy preview

SwaggerSpy

GitHubundeadsec/swaggerspy

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

api-securityinformation-gatheringosint+1
3224 months ago
JS-Secret-Hunter preview

JS-Secret-Hunter

GitHubsohelyousef/js-secret-hunter

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

crawlerinformation-gatheringpenetration-testing+3
8 months ago
Photon preview

Photon

GitHubs0md3v/photon

Incredibly fast crawler designed for OSINT.

crawlerdns-subdomain-enumerationemail-harvesting+5
13.3k1 month ago
jsluicepp preview

jsluicepp

GitHub0x999-x/jsluicepp

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

api-security-testinginformation-gatheringreconnaissance+3
3052 years ago
golddigger preview

golddigger

GitHubustayready/golddigger

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

data-exfiltrationinformation-gatheringpenetration-testing+1
1983 years ago
morf preview

morf

GitHubamrudesh1/morf

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

android-securityios-securitymobile-security+4
872 months ago
ccs preview

ccs

GitHubnccgroup/ccs

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…

code-analysisdevsecopssecret-detection+2
1143 years ago
SubDomainizer preview

SubDomainizer

GitHubnsonaniya2010/subdomainizer

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

cloud-securityinformation-gatheringosint+2
1.9k21 days ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

authenticationcloud-securitydevsecops+3
5037 months ago
pillager preview

pillager

GitHubbrittonhayes/pillager

Pillage filesystems for sensitive information with Go 🔍

data-exfiltrationinformation-gatheringpenetration-testing+4
31710 months ago
GitMiner3 preview

GitMiner3

GitHubunkl4b/gitminer3

Tool for advanced mining for content on Github

code-analysisinformation-gatheringosint+3
5610 months ago
ClawGuard preview

ClawGuard

GitHubny1024/clawguard

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

ai-securityanomaly-detectioncode-analysis+5
265 months ago
Burp_Collector preview

Burp_Collector

GitHubsajibuu/burp_collector

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

api-security-testinginformation-gatheringpenetration-testing+4
102 years ago
Previous12Next