Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
caddy preview

caddy

GitHubcaddyserver/caddy

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

encryption-decryption-toolsgeneral-purpose-utilitiesweb-security
75.2k2 days ago
reproxy preview

reproxy

GitHubumputun/reproxy

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

api-securityauthentication-authorizationgeneral-purpose-utilities+2
1.3k3 days ago
squid preview

squid

GitHubsquid-cache/squid

Squid Web Proxy Cache - Source Code

authentication-authorizationdns-analysisgeneral-purpose-utilities+3
3.1k4 days ago
certbot preview

certbot

GitHubcertbot/certbot

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

authentication-authorizationcloud-securityconfiguration-auditing+3
33.2k5 days ago
macsurf preview

macsurf

GitHubmplsllc/macsurf

A modern web browser for Classic Mac OS 9 PowerPC. Real CSS3, ES5 JavaScript, native HTTPS. Built with CodeWarrior on the Carbon API.

cryptographyencryption-decryption-toolsweb-security
2689 days ago
httpgrep preview

httpgrep

GitHubnoptrix/httpgrep

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and TLS-cert vhosts.

crawlerinformation-gatheringpenetration-testing+3
3620 days ago
janusec preview

janusec

GitHubjanusec/janusec

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

api-securityauthenticationcloud-security+8
1.2k1 month ago
oproxy preview

oproxy

GitHubsauravrao637/oproxy

Open-source MITM proxy to intercept, inspect, and mock network traffic.

api-security-testingdns-analysisnetwork-security+4
6081 month ago
lulzbuster preview

lulzbuster

GitHubnoptrix/lulzbuster

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

fuzzinginformation-gatheringpenetration-testing+3
1411 month ago
bbscope preview

bbscope

GitHubsw33tlie/bbscope

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

cloud-securitydatabase-securityinformation-gathering+6
1.4k1 month ago
sish preview

sish

GitHubantoniomika/sish

HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.

general-purpose-utilitiesnetwork-securityutilities-frameworks+1
4.7k2 months ago
mkdev preview

mkdev

GitHubvenkatkrishna07/mkdev

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

dns-analysisencryption-decryption-toolsnetwork-security+3
1412 months ago
badssl.com preview

badssl.com

GitHubchromium/badssl.com

:lock: Memorable site for testing clients against bad SSL configs.

educationweb-security
3.0k2 months ago
CVE-2025-25198-PoC preview

CVE-2025-25198-PoC

GitHubgroppoxx/cve-2025-25198-poc

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

exploitationpassword-attackspenetration-testing+3
203 months ago
CVE-2025-68461 preview

CVE-2025-68461

GitHubgotr00t0day/cve-2025-68461

A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.

information-gatheringpenetration-testingreconnaissance+3
78 months ago
http-breakout-proxy preview

http-breakout-proxy

GitHubjbsouthe/http-breakout-proxy

HTTP Proxy Analysis for reverse engineering protocol communication

api-security-testinginformation-gatheringlog-analysis+5
638 months ago
sslsplit preview

sslsplit

GitHubdroe/sslsplit

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

encryption-decryption-toolsforensicsids-ips-evasion+5
1.9k10 months ago
CVE-2025-22870 preview

CVE-2025-22870

GitHubjoshuaprovoste/cve-2025-22870

Proof-of-concept for CVE-2025-22870 demonstrating HTTP proxy bypass in vulnerable versions (<0.36.0) of golang.org/x/net/http/httpproxy. Exploits…

exploitationnetwork-securityvulnerability-analysis+1
21 year ago
Previous123Next