Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1180 results
cve-2021-23369 preview

cve-2021-23369

GitHubdinhvaren/cve-2021-23369

Proof-of-concept exploit for CVE-2021-23369, demonstrating a specific vulnerability in a JavaScript-based application.

exploitationvulnerability-analysisweb-security
4 months ago
log4shell-honeypot preview

log4shell-honeypot

GitHubvulnerable-apps/log4shell-honeypot

Java application vulnerable to the CVE-2021-44228 (a.k.a log4shell) vulnerability

vulnerability-analysisweb-security
4 years ago
HSTP preview

HSTP

GitHubcagataycali/hstp

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

cryptographynetwork-securityutilities-frameworks+1
1552 years ago
Pentest-Mapper preview

Pentest-Mapper

GitHubanof-cyber/pentest-mapper

A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities

penetration-testingvulnerability-analysisweb-security
1193 years ago
CVE-2026-34828 preview

CVE-2026-34828

GitHub0xmrma/cve-2026-34828

listmonk’s Session Persistence After Password Reset and Password Change

authenticationexploitationpenetration-testing+2
15 months ago
CVE-2021-3130 preview

CVE-2021-3130

GitHubjet-pentest/cve-2021-3130

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

authenticationmisconfigurationpenetration-testing+2
5 years ago
xsscrapy preview

xsscrapy

GitHubdanmcinerney/xsscrapy

XSS spider - 66/66 wavsep XSS detected

fuzzingvulnerability-analysisweb-security+1
1.7k4 years ago
PwnXSS preview

PwnXSS

GitHubpwn0sec/pwnxss

PwnXSS: Vulnerability (XSS) scanner exploit

crawlervulnerability-analysisweb-security+1
8185 years ago
xsssniper preview

xsssniper

GitHubgbrindisi/xsssniper

An automatic XSS discovery tool

fuzzingvulnerability-analysisweb-security+1
4238 years ago
traxss preview

traxss

GitHubm4cs/traxss

traxss | Automated XSS Vulnerability Scanner Currently In Development 🐍 HACKTOBERFEST PROJECT 2019

penetration-testingvulnerability-analysisweb-security+1
1816 years ago
s3cXSSer preview

s3cXSSer

GitHubs3c-krd/s3cxsser

This extension will help you to detect GET/POST based XSS vulnerability in any website easily

penetration-testingvulnerability-analysisweb-security+1
2463 years ago
Wordpress-Default-Password preview

Wordpress-Default-Password

GitHubjenderal92/wordpress-default-password

python 2.7

password-attackspenetration-testingweb-security+1
3 months ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.2k2h 11m ago
awesome-appsec preview

awesome-appsec

GitHubparagonie/awesome-appsec

A curated list of resources for learning about application security

curated-resourceseducationlearning-paths-courses+2
7.1k1 year ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

anti-botids-ips-evasionmisconfiguration+4
3.3k0 days ago
burpa preview

burpa

GitHub0x4d31/burpa

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

api-security-testingdevsecopsvulnerability-scanners+1
5369 years ago
wahh_extras preview

wahh_extras

GitHubsix2dez/wahh_extras

The Web Application Hacker's Handbook - Extra Content

curated-resourceseducationlearning-paths-courses+2
5713 years ago
Taipan preview

Taipan

GitHubenkomio/taipan

Web application vulnerability scanner

penetration-testingvulnerability-scannersweb-security+1
4625 years ago
Previous1…567…66Next