Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
1865 results
w3af preview

w3af

GitHubandresriancho/w3af

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

exploitationpenetration-testingvulnerability-scanners+3
4.9k6 years ago
cloudrasp-log4j2 preview

cloudrasp-log4j2

GitHubboundaryx/cloudrasp-log4j2

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

defensive-toolsexploit-frameworksvulnerability-analysis+1
1264 years ago
http2smugl preview

http2smugl

GitHubneex/http2smugl

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

penetration-testingvulnerability-analysisweb-application-exploitation+1
5641 year ago
SSTImap preview

SSTImap

GitHubvladko312/sstimap

Automatic SSTI detection tool with interactive interface

code-analysiscommand-and-controldynamic-code-analysis+6
1.6k19 days ago
CVE-2017-8056 preview

CVE-2017-8056

GitHubitzexploit/cve-2017-8056

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.

exploitationpenetration-testingvulnerability-analysis+1
1 year ago
CVE-2021-44026-PoC preview

CVE-2021-44026-PoC

GitHubskyllpro/cve-2021-44026-poc

Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubhappynote3966/cve-2018-7600

Exploit for CVE-2018-7600, a critical remote code execution vulnerability in Drupal core. Enables automated exploitation of unpatched Drupal sites…

exploitationpenetration-testingvulnerability-analysis+2
8 years ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerdynamic-code-analysisfuzzing+8
15.2k1 year ago
CVE-2022-31101 preview

CVE-2022-31101

GitHubkarthikuj/cve-2022-31101

Exploit for PrestaShop bockwishlist module 2.1.0 SQLi (CVE-2022-31101)

exploitationpenetration-testingvulnerability-analysis+1
254 years ago
Ethermint-CVE-2021-25837 preview

Ethermint-CVE-2021-25837

GitHubiczc/ethermint-cve-2021-25837

Proof-of-concept exploit for CVE-2021-25837 targeting Ethermint, demonstrating a critical vulnerability in Ethereum-compatible blockchain nodes.

exploitationvulnerability-analysisweb-application-exploitation
34 years ago
CVE-2023-33405 preview

CVE-2023-33405

GitHubhacip/cve-2023-33405

Proof-of-concept exploit for an open redirect vulnerability (CVE-2023-33405) in BlogEngine.NET CMS versions 3.3.8.0 and earlier, demonstrating…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.8k18 days ago
WebGoat preview

WebGoat

GitHubwebgoat/webgoat

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

ctfeducationlabs-practice+4
9.3k1 day ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.8k4 days ago
nikto preview

nikto

GitHubsullo/nikto

Nikto web server scanner

crawlerdynamic-code-analysisinformation-gathering+6
10.7k1 month ago
CVE-2022-0739 preview

CVE-2022-0739

GitHubdestr4ct/cve-2022-0739

Proof-of-Concept exploit (SQLI BookingPress before 1.0.11)

exploitationpenetration-testingvulnerability-analysis+2
123 years ago
CVE-2022-44268_By_Kyokito preview

CVE-2022-44268_By_Kyokito

GitHubchairat095/cve-2022-44268_by_kyokito

Proof-of-concept exploit for CVE-2022-44268, an arbitrary file read vulnerability in ImageMagick, enabling local file disclosure via crafted PNG…

exploitationpenetration-testingvulnerability-analysis+1
23 years ago
CVE-2025-29972 preview

CVE-2025-29972

GitHubthemehackers/cve-2025-29972

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

authentication-authorizationexploitationpenetration-testing+2
21 year ago
Previous12…100Next