Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1180 results
bunkerweb preview

bunkerweb

GitHubbunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

anti-botcloud-securitycontainer-security+6
10.9k
24 days ago
Scanner-and-Patcher preview

Scanner-and-Patcher

GitHubmalwareman007/scanner-and-patcher

A Web Vulnerability Scanner and Patcher

dns-subdomain-enumerationeducationexploitation+8
1741 year ago
cumulus preview

cumulus

GitHubtophat-cloud/cumulus

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

dynamic-analysis-sandboxingstatic-analysisvulnerability-scanners+1
404 years ago
Optiva-Framework preview

Optiva-Framework

GitHubjoker25000/optiva-framework

Optiva-Framework 🔎 Web Application Scanner🕵️

encryption-decryption-toolshash-analysisinformation-gathering+6
3148 years ago
See-SURF preview

See-SURF

GitHubin3tinct/see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

ai-securityreconnaissancevulnerability-scanners+2
3647 months ago
webvulscan preview

webvulscan

GitHubdermotblair/webvulscan

Web Application Vulnerability Scanner.

crawlerpenetration-testingvulnerability-scanners+2
15111 years ago
ravage preview

ravage

GitHubduriantaco/ravage

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

ai-securityctfdynamic-analysis-sandboxing+7
461 day ago
cve-2025-64446-fortiweb-exploit preview

cve-2025-64446-fortiweb-exploit

GitHuban5i/cve-2025-64446-fortiweb-exploit

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

educationexploitationpayload-development+5
19 months ago
CVE-2025-26054 preview

CVE-2025-26054

GitHubrohan-pt/cve-2025-26054

CVE-2025-26054

educationpenetration-testingvulnerability-analysis+2
1 year ago
ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-23457_2-2-3-1

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

api-securityauthentication-authorizationcode-analysis+6
1 year ago
CVE-2025-29927-test preview

CVE-2025-29927-test

GitHubkuzushiki/cve-2025-29927-test

Test application for CVE-2025-29927, designed for security study groups to demonstrate and verify the web vulnerability in a controlled environment.

educationpenetration-testingvulnerability-analysis+2
11 year ago
PENTEST-LAB preview

PENTEST-LAB

GitHubpannagkumaar/pentest-lab

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

ai-securityapi-securityauthentication+8
1 month ago
CVE-2025-55182_Vulnerable-Application preview

CVE-2025-55182_Vulnerable-Application

GitHubdeepankarkumar1/cve-2025-55182_vulnerable-application

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

ctfeducationlabs-practice+3
7 months ago
tracy preview

tracy

GitHubnccgroup/tracy

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

penetration-testingweb-security
5606 years ago
htcap preview

htcap

GitHubfcavallarin/htcap

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

crawlerfuzzingpenetration-testing+2
6284 years ago
xssmap preview

xssmap

GitHubjewel591/xssmap

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…

penetration-testingvulnerability-analysisweb-security+1
2706 years ago
PoW-Shield preview

PoW-Shield

GitHubruisiang/pow-shield

Project dedicated to fight Layer 7 DDoS with proof of work, with an additional WAF and controller. Completed with full set of features and…

web-security
4111 year ago
altair preview

altair

GitHubevilsocket/altair

Modular web vulnerability scanner with template-driven detection engine for automated testing of XSS, SQLi, LFI, RFI, and sensitive file/directory…

penetration-testingvulnerability-analysisweb-security+1
5115 years ago
Previous1…456…66Next