Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
theftfuzzer preview

theftfuzzer

GitHublc/theftfuzzer

TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.

fuzzingmisconfigurationvulnerability-scanners+1
319
6 years ago
CVE-2025-34291_cors_security_scanner preview

CVE-2025-34291_cors_security_scanner

GitHubamnnrth/cve-2025-34291_cors_security_scanner

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

api-security-testingmisconfigurationpenetration-testing+3
3 months ago
CORStest preview

CORStest

GitHubrub-nds/corstest

A simple CORS misconfiguration scanner

misconfigurationpenetration-testingvulnerability-scanners+1
4246 years ago
corsair_scan preview

corsair_scan

GitHubsantandersecurityresearch/corsair_scan

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

api-security-testingmisconfigurationvulnerability-scanners+1
1225 years ago
metahub preview

metahub

GitHubgabrielsoltz/metahub

Automated security findings enrichment and impact evaluation tool for AWS. Enriches vulnerability data with resource context, associations, and tags…

cloud-securityconfiguration-auditingincident-response+3
1776 months ago
CorsMe preview

CorsMe

GitHubshivangx01b/corsme

Cross Origin Resource Sharing MisConfiguration Scanner

misconfigurationpenetration-testingvulnerability-scanners+1
1705 years ago
lorsrf preview

lorsrf

GitHubmindpatch/lorsrf

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

fuzzingpenetration-testingvulnerability-scanners+1
2971 year ago
gcp_scanner preview

gcp_scanner

GitHubgoogle/gcp_scanner

GCP resource scanner that evaluates access levels of compromised credentials by enumerating cloud services, projects, and IAM permissions across…

cloud-securityinformation-gatheringreconnaissance+1
3688 months ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

authenticationexploitationpenetration-testing+3
12 years ago
DDOS-RootSec preview

DDOS-RootSec

GitHubr00ts3c/ddos-rootsec

Explore RootSec's DDOS Archive, featuring top-tier scanners, powerful botnets (Mirai & QBot) and other variants, high-impact exploits, advanced…

command-and-controlexploit-frameworksinformation-gathering+6
1.1k1 year ago
trivy-plugin-kubectl preview

trivy-plugin-kubectl

GitHubaquasecurity/trivy-plugin-kubectl

A Trivy plugin that scans the images of a kubernetes resource

cloud-securitycontainer-securitydevsecops+1
252 years ago
polaris preview

polaris

GitHubfairwindsops/polaris

Validation of best practices in your Kubernetes clusters

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
3.4k2 days ago
trivy-enforcer preview

trivy-enforcer

GitHubaquasecurity/trivy-enforcer

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

cloud-securitycontainer-securitydevsecops+3
206 years ago
http-pulse_ssl_vpn.nse preview

http-pulse_ssl_vpn.nse

GitHubr00tpgp/http-pulse_ssl_vpn.nse

Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510

exploitationinformation-gatheringpenetration-testing+3
187 years ago
drs-malware-scan preview

drs-malware-scan

GitHubaws-samples/drs-malware-scan

Perform file-based malware scan on your on-prem servers with AWS

cloud-securityincident-responsemalware-analysis+2
142 years ago