Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

api-securityapi-security-testingcrawler+12
38.3k20h 25m ago
PhEmail preview

PhEmail

GitHubdionach/phemail

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

email-harvestinginformation-gatheringosint+4
3496 years ago
LFI-FINDER preview

LFI-FINDER

GitHubcapture0x/lfi-finder

Automated scanner for detecting Local File Inclusion (LFI) vulnerabilities in web applications by analyzing URLs and testing payloads via geckodriver.

vulnerability-scannersweb-application-exploitationweb-security
3032 years ago
commix preview

commix

GitHubcommixproject/commix

Automated All-in-One OS Command Injection Exploitation Tool

exploitationpenetration-testingvulnerability-scanners+2
5.8k4 days ago
fuxploider preview

fuxploider

GitHubalmandin/fuxploider

File upload vulnerability scanner and exploitation tool.

exploitationpenetration-testingvulnerability-scanners+1
3.3k1 year ago
demiguise preview

demiguise

GitHubnccgroup/demiguise

HTA encryption tool for RedTeams

ids-ips-evasionpayload-generationphishing-tools+2
1.4k4 years ago
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
3251 month ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1217 months ago
toxssin preview

toxssin

GitHubt3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

exploitationinformation-gatheringpayload-generation+4
1.4k1 year ago
Pingpon-Exploit preview

Pingpon-Exploit

GitHub649/pingpon-exploit

Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.

exploitationosintreconnaissance+3
248 years ago
ginger preview

ginger

GitHubhawsec/ginger

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

api-securitydatabase-securityinformation-gathering+3
134 years ago
ImCurvin preview

ImCurvin

GitHubskokoo/imcurvin

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

ids-ips-evasioninformation-gatheringmisconfiguration+5
112 days ago
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE preview

CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE

GitHubjakabakos/cve-2023-27524-apache-superset-auth-bypass-and-rce

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

authentication-authorizationcommand-and-controldatabase-security+5
282 years ago
chusa preview

chusa

GitHubnu11secur1ty/chusa

chusa - 注射 - the new generation of sqlmap

database-securityexploitationinformation-gathering+3
38 months ago
CVE-2018-0114 preview

CVE-2018-0114

GitHuberemiel/cve-2018-0114

python2.7 script for JWT generation

authenticationencryption-decryption-toolsexploitation+3
25 years ago
CVE-2026-58424 preview

CVE-2026-58424

GitHubbridgeralderson/cve-2026-58424

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

authentication-authorizationexploitationpayload-development+4
226 days ago
tac_plus-pre-auth-rce preview

tac_plus-pre-auth-rce

GitHubtakeshixx/tac_plus-pre-auth-rce

tac_plus Pre-Auth Remote Command Execution Vulnerability (CVE-2023-45239 & CVE-2023-48643)

command-and-controlexploitationpenetration-testing+3
12 years ago
shocker preview

shocker

GitHubnccgroup/shocker

A tool to find and exploit servers vulnerable to Shellshock

exploitationpenetration-testingvulnerability-scanners+1
3273 years ago
Previous12Next