Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
184 results
wifipumpkin3 preview

wifipumpkin3

GitHubp0cl4bs/wifipumpkin3

Powerful framework for rogue access point attack.

captcha-bypassdns-analysisphishing+5
2.5k2 years ago
faraday_zap preview

faraday_zap

GitHubinfobyte/faraday_zap

Zap Extension for collaboration in Faraday

api-security-testingpenetration-testingvulnerability-scanners+2
27 months ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.9k3 days ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1268 months ago
BurpSuite_Pro_v1.7.37 preview

BurpSuite_Pro_v1.7.37

GitHubjas502n/burpsuite_pro_v1.7.37

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

api-security-testinginformation-gatheringpenetration-testing+4
567 years ago
zap-api-rust preview

zap-api-rust

GitHubzaproxy/zap-api-rust

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

api-securitypenetration-testingvulnerability-scanners+3
153 years ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
116 months ago
caido preview

caido

GitHubcaido/caido

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

penetration-testingweb-proxies-interceptionweb-security
2.6k4 months ago
hetty preview

hetty

GitHubdstotijn/hetty

An HTTP toolkit for security research.

penetration-testingweb-proxies-interceptionweb-security
12.5k3 months ago
proxy.py preview

proxy.py

GitHubabhinavsingh/proxy.py

💫 Ngrok FRP Alternative • ⚡ Fast • 🪶 Lightweight • 0️⃣ Dependency • 🔌 Pluggable • 😈 TLS interception • 🔒 DNS-over-HTTPS • 🔥 Poor Man's VPN • ⏪…

penetration-testingred-teamingutilities-frameworks+1
3.6k1 year ago
PwnFox preview

PwnFox

GitHubyeswehack/pwnfox

Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

penetration-testingweb-proxies-interceptionweb-security
1.4k4 years ago
morty preview

morty

GitHubasciimoo/morty

Privacy aware web content sanitizer proxy as a service

defensive-toolsprivacyweb-proxies-interception+1
5115 years ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
wotop preview

wotop

GitHubnishitm/wotop

Web on top of any protocol

network-securityweb-proxies-interception
1116 years ago
FiddleZAP preview

FiddleZAP

GitHubmalwareinfosec/fiddlezap

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

intrusion-detectionmalware-analysisthreat-intelligence+2
174 years ago
http-mcp-bridge preview

http-mcp-bridge

GitHubnccgroup/http-mcp-bridge

HTTP proxy bridge for security testing of remote MCP servers, allowing standard HTTP tools to send JSON-RPC messages and manage sessions.

api-securitypenetration-testingweb-proxies-interception+1
185 months ago
Burp-Recordadora preview

Burp-Recordadora

GitHubhackwarts12/burp-recordadora

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.

penetration-testingutilities-frameworksweb-proxies-interception+1
10 months ago
privaxy preview

privaxy

GitHubbarre/privaxy

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

adversarial-attackprivacyweb-proxies-interception+1
2.5k3 years ago
Previous12…11Next