Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
545 results
BurpSuite-collections preview

BurpSuite-collections

GitHubmr-xn/burpsuite-collections

有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using…

curated-resourceseducationpenetration-testing+2
4.0k
1 month ago
IntruderPayloads preview

IntruderPayloads

GitHub1n3/intruderpayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

curated-resourceseducationfuzzing+3
4.0k5 years ago
cariddi preview

cariddi

GitHubedoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

crawlerinformation-gatheringosint+4
3.8k4 days ago
send preview

send

GitHubtimvisee/send

📬 Simple, private file sharing. Mirror of https://gitlab.com/timvisee/send

encryption-decryption-toolsprivacyutilities-frameworks+1
5.9k1 year ago
WeblogicScan preview

WeblogicScan

GitHubrabbitmask/weblogicscan

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

exploitationinformation-gatheringpenetration-testing+3
2.3k3 years ago
openrasp preview

openrasp

GitHubbaidu/openrasp

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

anomaly-detectiondefensive-toolsdevsecops+2
3.0k1 year ago
dirmap preview

dirmap

GitHubh4ckforjob/dirmap

An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu…

information-gatheringpenetration-testingreconnaissance+2
3.4k1 year ago
Fast-Google-Dorks-Scan preview

Fast-Google-Dorks-Scan

GitHubivanglinkin/fast-google-dorks-scan

The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the…

information-gatheringosintreconnaissance+2
1.7k1 year ago
pwndrop preview

pwndrop

GitHubkgretzky/pwndrop

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

phishing-toolsred-teamingweb-security
2.3k6 years ago
w13scan preview

w13scan

GitHubw-digital-scanner/w13scan

Passive and active web vulnerability scanner with plugin-based detection for XSS, SQL injection, command injection, and sensitive file disclosure.…

penetration-testingvulnerability-scannersweb-security+1
1.9k4 years ago
php-malware-finder preview

php-malware-finder

GitHubnbs-system/php-malware-finder

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

malware-analysisstatic-analysisvulnerability-scanners+1
3434 years ago
Upload_Bypass preview

Upload_Bypass

GitHubsajibuu/upload_bypass

A simple tool for bypassing file upload restrictions.

exploitationpayload-generationpenetration-testing+2
9072 years ago
subjs preview

subjs

GitHublc/subjs

Fetches javascript file from a list of URLS or subdomains.

information-gatheringosintreconnaissance+1
8631 year ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4814 years ago
CVE-2019-11510 preview

CVE-2019-11510

GitHubprojectzeroindia/cve-2019-11510

Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)

exploitationinformation-gatheringpenetration-testing+3
3607 years ago
Farmer preview

Farmer

GitHubmdsecactivebreach/farmer

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

information-gatheringlateral-movementpassword-attacks+4
4295 years ago
pentest-machine preview

pentest-machine

GitHubdanmcinerney/pentest-machine

Automates some pentest jobs via nmap xml file

information-gatheringnetwork-securitypassword-attacks+3
3258 years ago
bfac preview

bfac

GitHubmazen160/bfac

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

information-gatheringreconnaissancevulnerability-scanners+1
5625 years ago
Previous12…31Next