Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
103 results
evilgrade preview

evilgrade

GitHubinfobyte/evilgrade

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

dns-analysisexploit-frameworkspayload-generation+4
1.3k
5 years ago
mitmproxy preview

mitmproxy

GitHubmitmproxy/mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

android-securityapi-securityapi-security-testing+12
45.1k9 days ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.8k1 day ago
MobileApp-Pentest-Cheatsheet preview

MobileApp-Pentest-Cheatsheet

GitHubtanprathan/mobileapp-pentest-cheatsheet

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

android-securitycurated-resourcesdynamic-code-analysis+9
5.3k2 years ago
caido preview

caido

GitHubcaido/caido

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

penetration-testingweb-proxies-interceptionweb-security
2.6k3 months ago
BurpSuite_Pro_v1.7.37 preview

BurpSuite_Pro_v1.7.37

GitHubjas502n/burpsuite_pro_v1.7.37

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

api-security-testinginformation-gatheringpenetration-testing+4
567 years ago
ratched preview

ratched

GitHubjohndoe31415/ratched

Ratched is a transparent Man-in-the-Middle TLS proxy intended for penetration testing

network-securitypenetration-testingweb-proxies-interception
335 years ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
106 months ago
burp-alfresco-referer-proxy-cve-2014-9301 preview

burp-alfresco-referer-proxy-cve-2014-9301

GitHubottimo/burp-alfresco-referer-proxy-cve-2014-9301

Burp Suite extension exploiting CVE-2014-9301 in Alfresco Referer Proxy for targeted web application penetration testing.

exploitationpenetration-testingvulnerability-analysis+2
9 years ago
Aresius preview

Aresius

GitHub0xmarik/aresius

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

api-security-testingfuzzinginformation-gathering+6
25 days ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.7k22h 44m ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k6 months ago
pentest-copilot preview

pentest-copilot

GitHubbugbasesecurity/pentest-copilot

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

ai-securitycommand-and-controlctf+8
1.5k1 month ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
8911 month ago
pentest-pivoting preview

pentest-pivoting

GitHubt3l3machus/pentest-pivoting

A compact guide to network pivoting for penetration testings / CTF challenges.

ctfcurated-resourceseducation+5
2272 years ago
qyvora-toha3ee preview

qyvora-toha3ee

GitHubqyvora/qyvora-toha3ee

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

exploitationnetwork-securityosint+9
44 days ago
Modlishka preview

Modlishka

GitHubdrk1wi/modlishka

Modlishka. Reverse Proxy.

authenticationimpersonation-toolspenetration-testing+6
5.4k1 month ago
Ssh Mitm preview

Ssh Mitm

GitLabssh-mitm/ssh-mitm

Mirror moved — see GitHub and Codeberg

authenticationinformation-gatheringnetwork-security+3
2 months ago
Previous123456Next