Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
VTScanner preview

VTScanner

GitHubsamhaxr/vtscanner

A comprehensive Python-based security tool for file scanning, malware detection, and analysis in an ever-evolving cyber landscape.

hash-analysisinformation-gatheringmalware-analysis+1
112
3 years ago
attack-surface-framework preview

attack-surface-framework

GitHubvmware-labs/attack-surface-framework

Tool to discover external and internal network attack surface

dns-subdomain-enumerationexploitationinformation-gathering+8
2062 years ago
RelayKing-Depth preview

RelayKing-Depth

GitHubdepthsecurity/relayking-depth

Dominate the domain. Relay to royalty.

exploitationids-ips-evasioninformation-gathering+7
3565 months ago
gotestwaf preview

gotestwaf

GitHubwallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-securityapi-security-testingpenetration-testing+4
1.8k1 year ago
catsploit preview

catsploit

GitHubcatsploit/catsploit

Automated penetration testing tool using Cyber Attack Techniques Scoring (CATS) to select and execute optimal attack scenarios via Metasploit, Nmap,…

exploit-frameworksinformation-gatheringpenetration-testing+3
3192 years ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
344 days ago
gato preview
Archived

gato

GitHubpraetorian-inc/gato

GitHub Actions Pipeline Enumeration and Attack Tool

devsecopsexploitationinformation-gathering+7
94 months ago
sub404 preview
Archived

sub404

GitHubr3curs1v3-pr0xy/sub404

A python tool to check subdomain takeover vulnerability

dns-analysispenetration-testingreconnaissance+3
3543 years ago
CVE-2026-41940-AuthBypass-Detector preview

CVE-2026-41940-AuthBypass-Detector

GitHubunteikyou/cve-2026-41940-authbypass-detector

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

authenticationpenetration-testingreconnaissance+2
24 months ago
scriptkiddi3 preview

scriptkiddi3

GitHubthecyberneh/scriptkiddi3

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

penetration-testingreconnaissancesubdomain-enumeration+1
1522 years ago
PenScope preview

PenScope

GitHubspider12223/penscope

Passive recon & attack surface mapper — zero requests sent

crawlerexploitationinformation-gathering+7
354 months ago
PY-Log4j-RCE-Scanner preview

PY-Log4j-RCE-Scanner

GitHubmrharshvardhan/py-log4j-rce-scanner

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

dns-analysisexploitationreconnaissance+3
43 years ago
ElectricEye preview

ElectricEye

GitHubjonrau1/electriceye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

cloud-securityconfiguration-auditingdevsecops+5
1.0k1 year ago
Garud preview

Garud

GitHubr0x4r/garud

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

penetration-testingreconnaissancesubdomain-enumeration+2
8114 months ago
Mr.SIP preview

Mr.SIP

GitHubmeliht/mr.sip

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

fuzzinginformation-gatheringpassword-cracking+2
4311 month ago
wodat preview

wodat

GitHubinitroot/wodat

Windows Oracle Database Attack Toolkit

database-securitypassword-attackspenetration-testing+1
794 years ago
wp2shell-rce preview

wp2shell-rce

GitHubjohnlodan/wp2shell-rce

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

penetration-testingreconnaissancevulnerability-analysis+4
31 month ago
See-SURF preview

See-SURF

GitHubin3tinct/see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

ai-securityreconnaissancevulnerability-scanners+2
3646 months ago
Previous12Next