Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
98 results
birp preview

birp

GitHubsensepost/birp

Big Iron Recon & Pwnage

information-gatheringpenetration-testingreconnaissance+2
1258 years ago
FiddleZAP preview

FiddleZAP

GitHubmalwareinfosec/fiddlezap

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

intrusion-detectionmalware-analysisthreat-intelligence+2
174 years ago
faraday_burp preview

faraday_burp

GitHubinfobyte/faraday_burp

Burp Extension for collaboration in Faraday

api-security-testingdevsecopspenetration-testing+3
136 months ago
frida-interception-and-unpinning preview

frida-interception-and-unpinning

GitHubhttptoolkit/frida-interception-and-unpinning

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

android-securityios-securitymobile-app-pentesting+4
2.3k3 days ago
proxify preview

proxify

GitHubprojectdiscovery/proxify

A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.

packet-sniffing-analysispenetration-testingweb-proxies-interception+1
3.1k1 year ago
ExternalC2 preview

ExternalC2

GitHubryhanson/externalc2

A library for integrating communication channels with the Cobalt Strike External C2 server

command-and-controlexploit-frameworkspayload-development+3
2898 years ago
ssl-kill-switch3 preview

ssl-kill-switch3

GitHubnyamisty/ssl-kill-switch3

Next Generation SSLKillSwitch with much more support!

ios-securitymobile-app-pentestingmobile-security+3
7552 years ago
mallory preview

mallory

GitHubjustmao945/mallory

HTTP/HTTPS proxy over SSH

general-purpose-utilitiesnetwork-securityweb-proxies-interception
3242 years ago
BurpSuiteJSBeautifier preview

BurpSuiteJSBeautifier

GitHubirsdl/burpsuitejsbeautifier

Burp Suite JS Beautifier

code-analysisdebuggersweb-proxies-interception+1
10112 years ago
BurpSuiteSharpenerEx preview

BurpSuiteSharpenerEx

GitHubirsdl/burpsuitesharpenerex

This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.

penetration-testingutilities-frameworksweb-proxies-interception+1
871 month ago
ritm preview

ritm

GitHubargos83/ritm

Ruby In The Middle (HTTP/HTTPS interception proxy)

dynamic-analysis-sandboxingpenetration-testingweb-proxies-interception+1
1007 years ago
go-http-proxy-to-socks preview

go-http-proxy-to-socks

GitHubshadowy-pycoder/go-http-proxy-to-socks

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

dns-analysisdns-fuzzingids-ips-evasion+6
702 months ago
auto-repeater preview

auto-repeater

GitHubxnl-h4ck3r/auto-repeater

Automated HTTP Request Repeating With Burp Suite

fuzzingpenetration-testingweb-proxies-interception+1
383 years ago
gofireprox preview

gofireprox

GitHubmr-pmillz/gofireprox

FireProx written in Go

ids-ips-evasionpenetration-testingred-teaming+2
202 years ago
http_bridge preview

http_bridge

GitHubalejandro-llanes/http_bridge

SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…

ids-ips-evasionred-teamingweb-proxies-interception
85 years ago
CVE-2025-32407 preview

CVE-2025-32407

GitHubdiegovargasj/cve-2025-32407

Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…

dns-analysisexploitationmobile-security+6
1 year ago
httptoolkit preview

httptoolkit

GitHubhttptoolkit/httptoolkit

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

api-security-testinggeneral-purpose-utilitiespenetration-testing+1
3.6k7 months ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
8901 month ago
Previous123456Next