Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
884 results
fisy-fuzz preview

fisy-fuzz

GitHub0xricksanchez/fisy-fuzz

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

exploitationfuzzingvulnerability-analysis
1503 years ago
raider preview

raider

GitHubowasp/raider

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

api-security-testingauthenticationpenetration-testing+3
1013 years ago
smod preview

smod

GitHub0x0mar/smod

MODBUS Penetration Testing Framework

fuzzinginformation-gatheringnetwork-security+3
9510 years ago
Apkx-Hunter preview

Apkx-Hunter

GitHubsyscallx-18113/apkx-hunter

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

android-securityinformation-gatheringmachine-learning+7
932 days ago
KaliIntelligenceSuite preview

KaliIntelligenceSuite

GitHubchopicalqui/kaliintelligencesuite

Automated intelligence-gathering framework that orchestrates Kali Linux tools and public APIs to collect, store, and analyze reconnaissance data for…

information-gatheringosintpenetration-testing+3
994 years ago
CVE-2024-53677-S2-067 preview

CVE-2024-53677-S2-067

GitHubtam-k592/cve-2024-53677-s2-067

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

exploitationpayload-developmentpenetration-testing+3
951 year ago
Adversarial-Detection-Engineering-Framework preview

Adversarial-Detection-Engineering-Framework

GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

curated-resourcesdefensive-toolseducation+7
616 months ago
mole preview

mole

GitHubztgrace/mole

Framework for identifying and exploiting out-of-band (OOB) application vulnerabilities with a custom DNS/token server, Burp Suite extension, and…

penetration-testingvulnerability-analysisweb-application-exploitation
586 years ago
Winstrument preview

Winstrument

GitHubnccgroup/winstrument

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

binary-analysisdynamic-code-analysisreverse-engineering+1
686 years ago
qlcoder preview

qlcoder

GitHubneuralprogram/qlcoder

Agentic Framework for Synthesizing CodeQL Queries

ai-assisted-reversingcode-analysispapers-research+3
2620 days ago
aether preview

aether

GitHubl33tdawg/aether

AI Smart Contract Security Analysis and PoC Generation Framework

ai-securitybinary-analysiscryptography+7
664 months ago
bof preview

bof

GitHuborange-cyberdefense/bof

BOF (Boiboite Opener Framework) is a testing framework for industrial protocols implementations and devices.

exploitationfuzzinginformation-gathering+6
533 years ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
232 days ago
SucoshScanny preview

SucoshScanny

GitHubmustafabilgici/sucoshscanny

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

code-analysissecret-detectionstatic-code-analysis+3
392 years ago
FIASSE preview

FIASSE

GitHubowasp/fiasse

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

code-analysiscurated-resourcesdevsecops+7
141 month ago
trevex preview

trevex

GitHubcispa/trevex

Automated Vulnerability Detection Framework for Transient Execution Vulnerabilities (IEEE S&P '26)

binary-analysiseducationexploitation+4
365 months ago
CVE-2022-22965_PoC preview

CVE-2022-22965_PoC

GitHubalt3kx/cve-2022-22965_poc

Spring Framework RCE (Quick pentest notes)

educationexploitationpayload-generation+3
174 years ago
CVE-2022-22963_Reverse-Shell-Exploit preview

CVE-2022-22963_Reverse-Shell-Exploit

GitHubj0ey17/cve-2022-22963_reverse-shell-exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify…

exploitationpayload-generationpenetration-testing+3
243 years ago
Previous1…363738…50Next