Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
74 results
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.7k
3 days ago
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.8k8 days ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.9k10h 12m ago
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.4k23 days ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerdynamic-code-analysisfuzzing+8
15.2k1 year ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.1k29 days ago
WhatWeb preview

WhatWeb

GitHuburbanadventurer/whatweb

Next generation web scanner

crawlerdynamic-code-analysisinformation-gathering+9
6.9k6 months ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.6k5 months ago
Vxscan preview

Vxscan

GitHubal0ne/vxscan

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

crawlerinformation-gatheringosint+7
1.8k6 years ago
byp4xx preview

byp4xx

GitHublobuhi/byp4xx

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

information-gatheringpenetration-testingwaf-bypass+2
1.9k3 years ago
htrace.sh preview

htrace.sh

GitHubtrimstray/htrace.sh

My simple Swiss Army knife for http/https troubleshooting and profiling.

dns-subdomain-enumerationinformation-gatheringpenetration-testing+3
3.9k1 year ago
CF-Hero preview

CF-Hero

GitHubmusana/cf-hero

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

dns-analysisfingerprint-spoofinginformation-gathering+5
2.6k3 months ago
identYwaf preview

identYwaf

GitHubstamparm/identywaf

Blind WAF identification tool

information-gatheringvulnerability-scannerswaf-bypass+1
75623 days ago
BurpSuite_403Bypasser preview

BurpSuite_403Bypasser

GitHubsting8k/burpsuite_403bypasser

Burpsuite Extension to bypass 403 restricted directory

ids-ips-evasioninformation-gatheringpenetration-testing+2
1.7k5 years ago
bypass-firewalls-by-DNS-history preview

bypass-firewalls-by-DNS-history

GitHubvincentcox/bypass-firewalls-by-dns-history

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

dns-analysispenetration-testingreconnaissance+2
1.3k6 years ago
hakoriginfinder preview

hakoriginfinder

GitHubhakluke/hakoriginfinder

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

information-gatheringreconnaissancewaf-bypass+1
1.1k2 months ago
requests-ip-rotator preview

requests-ip-rotator

GitHubge0rg3/requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

crawlerids-ips-evasioninformation-gathering+5
1.7k2 months ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
8981 month ago
Previous12345Next