Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
10 results
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

CLI tool for automating HTTP request routing through Burp Suite proxy to load reconnaissance URLs and streamline web application security testing…

penetration-testingreconnaissancescripting-automation+2
10
5 months ago
cowitness preview

cowitness

GitHubstolenusername/cowitness

Multi-protocol server (HTTP, HTTPS, DNS) for logging requests and customizing responses during web application testing and red team engagements.

dns-analysisinformation-gatheringpenetration-testing+3
1252 years ago
birp preview

birp

GitHubsensepost/birp

TN3270 proxy for mainframe security assessments. Intercepts, displays hidden fields, and allows modification of protected fields to bypass…

information-gatheringpenetration-testingreconnaissance+2
1258 years ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

fingerprint-spoofinginformation-gatheringosint+6
88618 days ago
Ssh Mitm preview

Ssh Mitm

GitLabssh-mitm/ssh-mitm

Man-in-the-middle SSH proxy for security audits and penetration testing. Intercepts SSH, SCP, and SFTP sessions with support for agent and port…

authenticationinformation-gatheringnetwork-security+3
2 months ago
hyperfox preview

hyperfox

GitHubmalfunkt/hyperfox

Transparent HTTP/HTTPS MITM proxy that intercepts, records, and logs traffic between two endpoints for security auditing and traffic analysis.

information-gatheringpacket-sniffing-analysispenetration-testing+1
1.6k6 years ago
CVE-2025-53770-Vulnerable-Scanner preview

CVE-2025-53770-Vulnerable-Scanner

GitHubimbas007/cve-2025-53770-vulnerable-scanner

Python script to scan SharePoint hosts for CVE-2025-53770 using custom payloads, with optional Burp Suite proxy interception for traffic analysis and…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
BurpSuite-Grand-Master-Tools preview

BurpSuite-Grand-Master-Tools

GitHubnu11secur1ty/burpsuite-grand-master-tools

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

penetration-testingreconnaissancescripting-automation+3
29 months ago
sandcat preview

sandcat

GitHubsyhunt/sandcat

An open-source, pentest and developer-oriented web browser, using the power of Lua

information-gatheringpenetration-testingutilities-frameworks+2
5502 years ago
LinkedIntel preview

LinkedIntel

GitHubtwo06/linkedintel

Automatically extracts LinkedIn profiles from API responses while browsing via Burp, exporting names, titles, locations, and profile URLs to CSV.

information-gatheringosintreconnaissance+1
1101 year ago