Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
336 results
cirrusgo preview

cirrusgo

GitHubph33rr/cirrusgo

A fast tool to scan SAAS,PAAS App written in Go

cloud-securityinformation-gatheringvulnerability-scanners+1
854 years ago
navgix preview

navgix

GitHubhakaioffsec/navgix

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

fuzzingmisconfigurationvulnerability-scanners+1
753 years ago
crlfuzz preview

crlfuzz

GitHubdwisiswant0/crlfuzz

A fast tool to scan CRLF vulnerability written in Go

fuzzingvulnerability-scannersweb-security
1.6k4 years ago
CVE-2025-66478-github-patcher preview

CVE-2025-66478-github-patcher

GitHubjibaru/cve-2025-66478-github-patcher

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

code-analysisdevsecopssupply-chain-security+2
10 months ago
ppmap preview

ppmap

GitHubkleiton0x00/ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

exploitationpenetration-testingvulnerability-scanners+2
5184 years ago
jsleak preview
Archived

jsleak

GitHub0xteles/jsleak

a Go code to detect leaks in JS files via regex patterns

information-gatheringosintreconnaissance+3
1514 years ago
mantra preview

mantra

GitHubbrosck/mantra

「🔑」A tool used to hunt down API key leaks in JS files and pages

information-gatheringsecret-detectionvulnerability-scanners+1
9467 months ago
vulnknox preview

vulnknox

GitHubiqzer0/vulnknox

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

penetration-testingvulnerability-scannersweb-application-exploitation+1
72 years ago
kyubisweep preview

kyubisweep

GitHubtanmayshahane/kyubisweep

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

code-analysisconfiguration-auditingdevsecops+3
49 months ago
CVE-2026-57517-CWP preview

CVE-2026-57517-CWP

GitHubgagaltotal/cve-2026-57517-cwp

Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517

command-and-controlexploitationpenetration-testing+2
3 months ago
local-log4j-vuln-scanner preview
Archived

local-log4j-vuln-scanner

GitHubhillu/local-log4j-vuln-scanner

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

code-analysisdevsecopsstatic-analysis+3
3714 years ago
See-SURF preview

See-SURF

GitHubin3tinct/see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

ai-securityreconnaissancevulnerability-scanners+2
3617 months ago
goGetBucket preview

goGetBucket

GitHubglem0/gogetbucket

A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.

cloud-securityinformation-gatheringpenetration-testing+2
1167 years ago
ssrfuzz preview

ssrfuzz

GitHubryandamour/ssrfuzz

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

fuzzingvulnerability-scannersweb-application-exploitation+1
1845 years ago
proxylogscan preview

proxylogscan

GitHubdwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

exploitationinformation-gatheringpenetration-testing+3
1664 years ago
crlfmap preview

crlfmap

GitHubryandamour/crlfmap

CRLFMap is a tool to find HTTP Splitting vulnerabilities

fuzzingids-ips-evasionpenetration-testing+3
335 years ago
crlfmap preview

crlfmap

GitHubethicalhackingplayground/crlfmap

CRLFMap is a tool to find HTTP Splitting vulnerabilities

fuzzingvulnerability-scannersweb-security
256 years ago
at-doom-fortigate preview

at-doom-fortigate

GitHubjpiechowka/at-doom-fortigate

Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.

exploitationinformation-gatheringnetwork-security+3
52 years ago
Previous12…19Next