Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
Barcha preview

Barcha

GitHubs1n6h/barcha

Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates: Shodan enumeration of SSL hosts 🕵️‍♂️ Liveness &…

information-gatheringreconnaissancevulnerability-scanners+1
34
1 year ago
sss3 preview

sss3

GitHubhalencarjunior/sss3

Automated S3 bucket security scanner that tests domain lists for publicly accessible buckets with listing permissions, exporting results for cloud…

cloud-securityinformation-gatheringpenetration-testing+1
324 years ago
CVE-2025-55182-zoomeye preview

CVE-2025-55182-zoomeye

GitHubim-ezboy/cve-2025-55182-zoomeye

🔍 Next.js RCE Scanner (CVE-2025-55182) - Automated vulnerability scanner using Zoomeye search engine. Discovers targets via dorks and tests for…

exploitationinformation-gatheringpenetration-testing+3
88 months ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
63 months ago
csp-log4j preview

csp-log4j

GitHubrandomrobbiebf/csp-log4j

Finds CSP report urls and tests to see if they are vulnerable to log4j

information-gatheringreconnaissancevulnerability-scanners+2
23 years ago
mongobleedburp preview

mongobleedburp

GitHubj0lt-github/mongobleedburp

Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.

data-exfiltrationexploitationinformation-gathering+3
1 month ago
Wordpress-Vulnerability-Identification-Scripts preview

Wordpress-Vulnerability-Identification-Scripts

GitHubthatonesecguy/wordpress-vulnerability-identification-scripts

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

exploitationinformation-gatheringreconnaissance+2
23 years ago
web-application-firewall- preview

web-application-firewall-

GitHubnithylesh/web-application-firewall-

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

educationexploitationids-ips-evasion+5
32 years ago
dns-zone-transfer-test preview

dns-zone-transfer-test

GitHubrodney-o-c-melby/dns-zone-transfer-test

Automates Domain Name System (DNS) zone transfer testing. Checks for CVE-1999-0532 by automatically finding a given domains nameservers, and tests…

dns-analysisinformation-gatheringnetwork-security+3
31 year ago
S3-from-csp preview

S3-from-csp

GitHubrandomrobbiebf/s3-from-csp

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

cloud-infrastructure-securitycloud-securityinformation-gathering+2
13 years ago
MongoBleed-CVE-2025-14847-Fully-Automated-scanner preview

MongoBleed-CVE-2025-14847-Fully-Automated-scanner

GitHubcadgoose/mongobleed-cve-2025-14847-fully-automated-scanner

Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit.

exploitationinformation-gatheringreconnaissance+2
17 months ago
CVE-2022-22536_SAP_Request_Smuggling_Scanner preview

CVE-2022-22536_SAP_Request_Smuggling_Scanner

GitHubabrewer251/cve-2022-22536_sap_request_smuggling_scanner

Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted…

exploitationnetwork-securitypenetration-testing+3
9 months ago
fire-wall-server preview

fire-wall-server

GitHubnosie12/fire-wall-server

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

defensive-toolseducationintrusion-detection+3
1 year ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubgraysignal/cve-2025-3248

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

exploitationpenetration-testingvulnerability-analysis+3
11 year ago
cipherscan preview

cipherscan

GitHubmozilla/cipherscan

A very simple way to find out which SSL ciphersuites are supported by a target.

configuration-auditingcryptographynetwork-security+1
2.0k1 year ago
graphql-cop preview

graphql-cop

GitHubdolevf/graphql-cop

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

api-security-testingpenetration-testingvulnerability-scanners+1
6869 months ago
heartbleeder preview

heartbleeder

GitHubtitanous/heartbleeder

OpenSSL CVE-2014-0160 Heartbleed vulnerability test

information-gatheringnetwork-securitypenetration-testing+1
45212 years ago
autopentest-ai preview

autopentest-ai

GitHubbhavsec/autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

crawlereducationexploit-frameworks+8
2145 months ago
Previous1234Next