Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k
5 months ago
BurpSuite-Plugin preview

BurpSuite-Plugin

GitHubjas502n/burpsuite-plugin

Plugin For BurpSuite (Pentester)

penetration-testing-frameworksvulnerability-analysisweb-application-exploitation+2
373 years ago
Extractor preview

Extractor

GitHubnccgroup/extractor

Extension adds a new tab in Burp Suite called Extractor

encryption-decryption-toolspenetration-testingscripting-automation+3
417 years ago
readable-thrift preview

readable-thrift

GitHubnccgroup/readable-thrift

Human-friendly Thrift encoder/decoder

penetration-testingreverse-engineeringutilities-frameworks+2
244 years ago
WCFDSer-ngng preview

WCFDSer-ngng

GitHubnccgroup/wcfdser-ngng

A Burp Extender plugin, that will make binary soap objects readable and modifiable.

api-security-testingpenetration-testingvulnerability-analysis+3
314 years ago
webcgi-exploits preview

webcgi-exploits

GitHubwofeiwo/webcgi-exploits

Multi-language web CGI interfaces exploits.

exploitationpayload-generationremote-access-tool+2
3954 years ago
ProxySqlMap preview

ProxySqlMap

GitHubianxtianxt/proxysqlmap

From Proxy to SqlMapApi

penetration-testingvulnerability-scannersweb-application-exploitation+2
16 years ago
BurpSuite_Pro_v1.7.37 preview

BurpSuite_Pro_v1.7.37

GitHubjas502n/burpsuite_pro_v1.7.37
api-security-testinginformation-gatheringpenetration-testing+4
567 years ago
cve-2022-1040 preview

cve-2022-1040

GitHubkeith-amateur/cve-2022-1040

Save the trouble to open the burpsuite...

exploitationpenetration-testingvulnerability-analysis+2
33 years ago
burp-alfresco-referer-proxy-cve-2014-9301 preview

burp-alfresco-referer-proxy-cve-2014-9301

GitHubottimo/burp-alfresco-referer-proxy-cve-2014-9301
exploitationpenetration-testingvulnerability-analysis+2
9 years ago
CVE-2025-53770-Vulnerable-Scanner preview

CVE-2025-53770-Vulnerable-Scanner

GitHubimbas007/cve-2025-53770-vulnerable-scanner
exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2017-6640-POC preview

CVE-2017-6640-POC

GitHubhemp3l/cve-2017-6640-poc

Proof of concept for CVE-2017-6640 as burp extension

authenticationexploitationpenetration-testing+3
26 years ago
cve-2021-33045 preview

cve-2021-33045

GitHubdongpohezui/cve-2021-33045
authenticationexploitationvulnerability-analysis+2
94 years ago
reDOM preview

reDOM

GitHubweirdmachine64/redom

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

api-security-testingdynamic-analysis-sandboxinginformation-gathering+5
153 months ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1197 months ago
react2shell_analyzer preview

react2shell_analyzer

GitHubbenrich127n/react2shell_analyzer

a dart package to analyze CVE-2025-55182 react2shell

dynamic-analysis-sandboxingpenetration-testingvulnerability-analysis+3
18 months ago
toolbox preview

toolbox

GitHubgo-appsec/toolbox

Collaborative application security testing between humans and agents via CLI and MCP

api-security-testingcrawlerdynamic-analysis-sandboxing+8
411 day ago
sign-saboteur preview

sign-saboteur

GitHubd0ge/sign-saboteur

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

authentication-authorizationcryptographyfuzzing+7
1721 year ago
Previous12Next