Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
512 results
GPEWebDefender preview

GPEWebDefender

GitHubtheretardedelon/gpewebdefender

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

anomaly-detectiondefensive-toolsintrusion-detection+2
2
1 month ago
webanalyze preview

webanalyze

GitHubrverton/webanalyze

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

crawlerinformation-gatheringosint+3
1.2k13 days ago
gofireprox preview

gofireprox

GitHubmr-pmillz/gofireprox

FireProx written in Go

ids-ips-evasionpenetration-testingred-teaming+2
202 years ago
godirb preview

godirb

GitHubmycode83/godirb

Fast and easy-to-use directory brute-forcer written in Go.

fuzzinginformation-gatheringpenetration-testing+3
514 days ago
wappalyzergo preview

wappalyzergo

GitHubprojectdiscovery/wappalyzergo

A high performance go implementation of Wappalyzer Technology Detection Library

crawlerinformation-gatheringreconnaissance+2
1.1k5 days ago
CVE-2023-44761_ConcreteCMS-Stored-XSS---Forms preview

CVE-2023-44761_ConcreteCMS-Stored-XSS---Forms

GitHubsromanhu/cve-2023-44761_concretecms-stored-xss---forms

Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Form of the…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4081 year ago
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.3k1 day ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
cent preview

cent

GitHubxm1k3/cent

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

curated-resourcespenetration-testingvulnerability-scanners+1
1.1k3 months ago
log4shell-tools preview

log4shell-tools

GitHubalexbakker/log4shell-tools

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

dns-analysisexploitationpenetration-testing+3
862 years ago
CVE-2026-20896 preview

CVE-2026-20896

GitHubrz1027/cve-2026-20896

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

authenticationeducationexploitation+5
62 months ago
RatRace preview

RatRace

GitHubbogdanticu88/ratrace

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

api-security-testingdevsecopsexploitation+5
105 months ago
fix-react2shell-next preview

fix-react2shell-next

GitHubsaied25/fix-react2shell-next

🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.

educationexploitationgeneral-purpose-utilities+2
4 days ago
CVE-2018-8062 preview

CVE-2018-8062

GitHuboscarakaelvis/cve-2018-8062

Persistent XSS on Comtrend AR-5387un router

exploitationpenetration-testingphishing-tools+3
12 years ago
CVE-2023-36146 preview

CVE-2023-36146

GitHubleonardobg/cve-2023-36146

Proof-of-concept for authenticated stored cross-site scripting (XSS) vulnerability in Multilaser RE 170 router firmware 2.2.6733, with reproduction…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
web-check preview

web-check

GitHublissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

dns-analysisemail-harvestinginformation-gathering+10
35.0k2 days ago
akto preview

akto

GitHubakto-api-security/akto

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

api-securityapi-security-testingdevsecops+2
1.5k1 day ago
Previous12…29Next