Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
190 results
webcgi-exploits preview

webcgi-exploits

GitHubwofeiwo/webcgi-exploits

Multi-language web CGI interfaces exploits.

exploitationpayload-generationremote-access-tool+2
395
3 years ago
Kittysploit-framework preview

Kittysploit-framework

GitHubsia-iotechnology/kittysploit-framework

Python Exploitation Framework, V8 Engine Debugger, Proxy interceptor, marketplace, post-exploitation, backdoor generator,....

ai-securitycommand-and-controldebuggers+8
6072 days ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

api-security-testingdevsecopsdynamic-analysis-sandboxing+5
15.6k21h 47m ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.7k1h 14m ago
WebHackersWeapons preview

WebHackersWeapons

GitHubhahwul/webhackersweapons

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

curated-resourceseducationexploit-frameworks+7
5.0k5 months ago
squid preview

squid

GitHubsquid-cache/squid

Squid Web Proxy Cache - Source Code

authentication-authorizationdns-analysisgeneral-purpose-utilities+3
3.1k6 days ago
nodriver preview

nodriver

GitHubultrafunkamsterdam/nodriver

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

anti-botcaptcha-bypasscrawler+8
4.7k3 months ago
proxy.py preview

proxy.py

GitHubabhinavsingh/proxy.py

💫 Ngrok FRP Alternative • ⚡ Fast • 🪶 Lightweight • 0️⃣ Dependency • 🔌 Pluggable • 😈 TLS interception • 🔒 DNS-over-HTTPS • 🔥 Poor Man's VPN • ⏪…

penetration-testingred-teamingutilities-frameworks+1
3.5k1 year ago
caido preview

caido

GitHubcaido/caido

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

penetration-testingweb-proxies-interceptionweb-security
2.5k2 months ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
88614 days ago
betwixt preview

betwixt

GitHubkdzwinel/betwixt

:zap: Web Debugging Proxy based on Chrome DevTools Network panel.

debuggerspacket-sniffing-analysisweb-proxies-interception+1
4.6k7 years ago
httplab preview

httplab

GitHubqustavo/httplab

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

api-security-testingdebuggersgeneral-purpose-utilities+1
4.1k2 years ago
requests-ip-rotator preview

requests-ip-rotator

GitHubge0rg3/requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

crawlerids-ips-evasioninformation-gathering+5
1.7k1 month ago
neo preview

neo

GitHub4ier/neo

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

ai-securityapi-securitycrawler+8
7483 months ago
sandcat preview

sandcat

GitHubsyhunt/sandcat

An open-source, pentest and developer-oriented web browser, using the power of Lua

information-gatheringpenetration-testingutilities-frameworks+2
5502 years ago
morty preview

morty

GitHubasciimoo/morty

Privacy aware web content sanitizer proxy as a service

defensive-toolsprivacyweb-proxies-interception+1
5142 years ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
n00bRAT preview

n00bRAT

GitHubabhishekkr/n00brat

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

command-and-controleducationfingerprint-spoofing+5
1747 years ago
Previous12…11Next