Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
227 results
apicheck preview

apicheck

GitHubowasp/apicheck

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

api-securityapi-security-testingdevsecops+3
37
1 year ago
apidetector preview

apidetector

GitHubbrinhosa/apidetector

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

api-security-testinginformation-gatheringreconnaissance+2
3801 year ago
airecon preview

airecon

GitHubpikpikcu/airecon

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

ai-securityeducationexploitation+6
1.1k24 days ago
abdal-cve-2026-63030 preview

abdal-cve-2026-63030

GitHubebrasha/abdal-cve-2026-63030

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

api-security-testinginformation-gatheringpenetration-testing+2
42 months ago
restler-fuzzer preview

restler-fuzzer

GitHubmicrosoft/restler-fuzzer

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

api-security-testingcloud-securityfuzzing+2
3.0k7 months ago
s3crets_scanner preview

s3crets_scanner

GitHubeilonh/s3crets_scanner

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

cloud-infrastructure-securitycloud-securitysecret-detection+1
5733 years ago
JS-Secret-Hunter preview

JS-Secret-Hunter

GitHubsohelyousef/js-secret-hunter

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

crawlerinformation-gatheringpenetration-testing+3
8 months ago
sj preview

sj

GitHubbishopfox/sj

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

api-security-testingpenetration-testingvulnerability-scanners+1
8793 days ago
CVE-2023-2732 preview

CVE-2023-2732

GitHubap0dexme0/cve-2023-2732

Perform With Massive Authentication Bypass (Wordpress Mstore-API)

authenticationeducationpenetration-testing+2
23 years ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.2k13 days ago
w3af preview

w3af

GitHubandresriancho/w3af

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

exploitationpenetration-testingvulnerability-scanners+3
4.9k6 years ago
scant3r preview

scant3r

GitHubmindpatch/scant3r

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

penetration-testingscripting-automationvulnerability-scanners+2
6861 day ago
HikvisionExploiter preview

HikvisionExploiter

GitHubtamim1089/hikvisionexploiter

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

command-and-controlencryption-decryption-toolsexploitation+8
3889 months ago
Egyscan preview

Egyscan

GitHubdragonked2/egyscan

Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

crawlerinformation-gatheringpenetration-testing+4
3031 month ago
bulwark preview

bulwark

GitHubsoftrams/bulwark

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

api-securityauthentication-authorizationconfiguration-auditing+3
18710 months ago
Clickjacking-Tester preview

Clickjacking-Tester

GitHubd4vinci/clickjacking-tester

A python script designed to check if the website if vulnerable of clickjacking and create a poc

exploitationpenetration-testingvulnerability-scanners+2
1609 years ago
argumentinjectionhammer preview

argumentinjectionhammer

GitHubnccgroup/argumentinjectionhammer

A Burp Extension designed to identify argument injection vulnerabilities.

api-security-testingpenetration-testingvulnerability-scanners+2
1257 years ago
ccs preview

ccs

GitHubnccgroup/ccs

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…

code-analysisdevsecopssecret-detection+2
1143 years ago
Previous12…13Next