Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
285 results
CVE-2023-44487 preview

CVE-2023-44487

GitHubbcdannyboy/cve-2023-44487

Non-invasive HTTP/2 vulnerability scanner for CVE-2023-44487 that detects exploitable stream reset conditions by testing protocol downgrade and…

exploitationvulnerability-scannersweb-security
2472 years ago
ScanQLi preview

ScanQLi

GitHubbambish/scanqli

SQLi scanner to detect SQL vulns

penetration-testingvulnerability-scannersweb-security
2057 years ago
log4j-detect preview

log4j-detect

GitHubtakito1812/log4j-detect

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

exploitationvulnerability-scannersweb-security
1954 years ago
HTTPoxyScan preview

HTTPoxyScan

GitHub1n3/httpoxyscan

HTTPoxy Exploit Scanner by 1N3 @CrowdShield

exploitationvulnerability-scannersweb-application-exploitation+1
1049 years ago
Jetleak-Testing-Script preview

Jetleak-Testing-Script

GitHubgdssecurity/jetleak-testing-script

Script to test if a server is vulnerable to the JetLeak vulnerability

vulnerability-analysisvulnerability-scannersweb-security
14411 years ago
optionsbleed preview

optionsbleed

GitHubhannob/optionsbleed

Proof-of-concept scanner for the Optionsbleed vulnerability (CVE-2017-9798) that tests Apache HTTP servers for memory leak via HTTP OPTIONS method.

vulnerability-scannersweb-securityweb-vulnerability-scanners
1476 years ago
Airachnid-Burp-Extension preview

Airachnid-Burp-Extension

GitHubspiderlabs/airachnid-burp-extension

A Burp Extension to test applications for vulnerability to the Web Cache Deception attack

penetration-testingvulnerability-scannersweb-application-exploitation+1
1418 years ago
Jeeves preview

Jeeves

GitHubferreiraklet/jeeves

Time-based blind SQL injection detection tool for recon and bug bounty. Accepts single URLs or lists, supports custom headers, proxy, and POST data…

penetration-testingvulnerability-scannersweb-security
2154 years ago
burp-text4shell preview

burp-text4shell

GitHubsilentsignal/burp-text4shell

Text4Shell scanner for Burp Suite

vulnerability-analysisvulnerability-scannersweb-security+1
1893 years ago
erebus preview

erebus

GitHubethicalhackingplayground/erebus

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

fuzzingpenetration-testingvulnerability-scanners+4
1335 years ago
XXRF-Shots preview

XXRF-Shots

GitHubsamhaxr/xxrf-shots

XXRF Shots - Useful for testing SSRF vulnerability

penetration-testingvulnerability-scannersweb-security
733 years ago
Log4J-Scanner preview

Log4J-Scanner

GitHub0xdexter0us/log4j-scanner

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

exploitationpenetration-testingvulnerability-scanners+3
1014 years ago
laravelN00b preview

laravelN00b

GitHubtismayil/laraveln00b

LaravelN00b .env Scanner

misconfigurationvulnerability-scannersweb-security
366 years ago
scanginx preview

scanginx

GitHubsouravbaghz/scanginx

Scanner For Nginx - Remote Integer Overflow Vulnerability

exploitationvulnerability-scannersweb-security
371 year ago
text4shellburpscanner preview

text4shellburpscanner

GitHubf0ng/text4shellburpscanner

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

exploitationpenetration-testingvulnerability-scanners+2
203 years ago
tomcat-cve-2020-1938-check preview

tomcat-cve-2020-1938-check

GitHubfatal0/tomcat-cve-2020-1938-check

Go-based scanner for Apache Tomcat AJP file read/inclusion vulnerability (CVE-2020-1938). Detects and exploits Ghostcat to read arbitrary files or…

exploitationnetwork-securityvulnerability-scanners+1
76 years ago
vulnknox preview

vulnknox

GitHubiqzer0/vulnknox

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

penetration-testingvulnerability-scannersweb-application-exploitation+1
71 year ago
CVE-2022-41404-DoS-Protection preview

CVE-2022-41404-DoS-Protection

GitHubfdjy1234/cve-2022-41404-dos-protection

Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection

configuration-auditingdefensive-toolseducation+2
17 days ago
Previous1234…16Next