Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
http-terminator preview

http-terminator

GitHubportswigger/http-terminator

AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms…

ai-securityexploitationfuzzing+8
120
1 month ago
rcekit preview

rcekit

GitHubkabiri-labs/rcekit

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

command-and-controlexploitationfuzzing+8
243 days ago
EvilVM preview

EvilVM

GitHubjephthai/evilvm

Forth-based compiler deployed as position-independent x86_64 shellcode, providing a remote code execution agent with interactive REPL over TCP, HTTP,…

command-and-controlexploit-frameworkspayload-development+7
2094 years ago
HP-HPLIP-Mass-CVE-checker-2026-09- preview

HP-HPLIP-Mass-CVE-checker-2026-09-

GitHubmurrez/hp-hplip-mass-cve-checker-2026-09-

Mass check/research exploit for HP HPLIP CVE-2026-91097–91106 (<3.26.6), PAPPL :8000 IPP probes + hpssd templates

exploitationinformation-gatheringiot-security+5
10 days ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5213 days ago
async-http-client-check preview

async-http-client-check

GitHubxiaoqimikko/async-http-client-check

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

defensive-toolsdevsecopsstatic-analysis+4
13 days ago
Roxy preview

Roxy

GitHubvid4l-07/roxy

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

api-security-testingpenetration-testingutilities-frameworks+3
617 days ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
1116 days ago
feroxfuzz preview

feroxfuzz

GitHubepi052/feroxfuzz

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

api-security-testingfuzzingutilities-frameworks+1
2228 months ago
httprobe preview

httprobe

GitHubtomnomnom/httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

dns-subdomain-enumerationgeneral-purpose-utilitiesinformation-gathering+7
3.1k4 years ago
CypherDog preview

CypherDog

GitHubsadprocessor/cypherdog

PoSh BloodHound Dog Whisperer

information-gatheringpenetration-testingreconnaissance+2
1943 years ago
burp2caido preview

burp2caido

GitHubcaido-community/burp2caido

A tool to migrate Burpsuite HTTP history to Caido

penetration-testingutilities-frameworksweb-proxies-interception+1
421 year ago
AutoRepeater preview

AutoRepeater

GitHubnccgroup/autorepeater

Automated HTTP Request Repeating With Burp Suite

api-security-testingauthentication-authorizationpenetration-testing+4
8944 years ago
burp-jq preview

burp-jq

GitHubsynacktiv/burp-jq

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

api-securityutilities-frameworksweb-proxies-interception
505 years ago
bbs preview

bbs

GitHubsynacktiv/bbs

bbs is a router for SOCKS and HTTP proxies. It exposes a SOCKS5 (or HTTP CONNECT) service and forwards incoming requests to proxies or chains of…

network-securitypenetration-testingred-teaming+2
992 months ago
BurpSuite-Grand-Master-Tools preview

BurpSuite-Grand-Master-Tools

GitHubnu11secur1ty/burpsuite-grand-master-tools

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

penetration-testingreconnaissancescripting-automation+3
210 months ago
hulk preview

hulk

GitHubgrafov/hulk

HULK DoS tool ported to Go with some additional features.

penetration-testingutilities-frameworksweb-security
9085 years ago
proxychains-ng preview

proxychains-ng

GitHubrofl0r/proxychains-ng

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…

command-and-controldata-exfiltrationgeneral-purpose-utilities+6
10.7k1 month ago
Previous123Next