Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1485 results
pcap-burp preview

pcap-burp

GitHubnccgroup/pcap-burp

Pcap importer for Burp

network-forensicspacket-sniffing-analysispenetration-testing+2
1135 years ago
HSTP preview

HSTP

GitHubcagataycali/hstp

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

cryptographynetwork-securityutilities-frameworks+1
1552 years ago
slipstream preview

slipstream

GitHubsamyk/slipstream

NAT Slipstreaming allows an attacker to remotely access any TCP/UDP services bound to a victim machine, bypassing the victim’s NAT/firewall, just by…

exploitationnetwork-securitypenetration-testing+2
2.0k3 years ago
proxify preview

proxify

GitHubprojectdiscovery/proxify

A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.

packet-sniffing-analysispenetration-testingweb-proxies-interception+1
3.1k11 months ago
oxo preview

oxo

GitHubostorlab/oxo

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

devsecopsmobile-securitynetwork-security+3
5803 days ago
seccubus preview

seccubus

GitHubseccubus/seccubus

Easy automated vulnerability scanning, reporting and analysis

defensive-toolslog-analysisnetwork-mapping+5
7136 years ago
rupture preview

rupture

GitHubdecrypto-org/rupture

A framework for BREACH and other compression-based crypto attacks

cryptographyexploitationpacket-sniffing-analysis+3
2387 years ago
docker-tor-hiddenservice-nginx preview

docker-tor-hiddenservice-nginx

GitHubopsxcq/docker-tor-hiddenservice-nginx

Easily setup a hidden service inside the Tor network

network-securityprivacyred-teaming+2
1727 years ago
DDos_Attack.py preview

DDos_Attack.py

GitHubakashblackhat/ddos_attack.py

NetSTRIK is a powerful DDoS (Distributed Denial of Service) attack tool that simulates heavy traffic to test the robustness and security of servers,…

network-securitypenetration-testingweb-security
1681 year ago
HASH preview

HASH

GitHubdatadog/hash

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

defensive-toolsnetwork-securitythreat-intelligence+1
1422 years ago
rapidresetclient preview

rapidresetclient

GitHubsecengjeff/rapidresetclient

Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)

exploitationnetwork-securitypenetration-testing+2
762 years ago
asa_tools preview

asa_tools

GitHubnetspi/asa_tools

Verification tools for CVE-2016-1287

exploitationnetwork-securitypenetration-testing+2
339 years ago
OpenSSL-CCS-Inject-Test preview

OpenSSL-CCS-Inject-Test

GitHubtripwire/openssl-ccs-inject-test

This script is designed for detection of vulnerable servers (CVE-2014-0224.) in a wide range of configurations. It attempts to negotiate using each…

exploitationnetwork-securitypenetration-testing+2
3912 years ago
zscan preview

zscan

GitHubzcyberseclab/zscan

A fast, customizable service detection tool powered by a flexible fingerprint system. It helps you identify services, APIs, and network…

network-securitypenetration-testingport-scanning+3
451 month ago
AV-Chaos-Monkey preview

AV-Chaos-Monkey

GitHubmdsadiqmd/av-chaos-monkey

Chaos Monkey but for Audio Video Testing (webRTC and UDP)

chaos-engineeringcloud-securitydevsecops+3
525 months ago
Woeful preview

Woeful

GitHubmercuryworkshop/woeful

Woeful is a tool that lets web apps to safely and securely connect to the outside internet without a complex backend.

dns-analysisnetwork-securitypacket-sniffing-analysis+2
141 year ago
CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS preview

CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS

GitHubgeorge0papasotiriou/cve-2026-11118-http-2-rapid-reset-ddos

Python PoC for CVE-2026-11118 demonstrating HTTP/2 Rapid Reset DDoS via RST_STREAM resource exhaustion; includes vulnerable server simulator and…

exploitationnetwork-securityvulnerability-analysis+1
16 days ago
MadeYouReset_Tester preview

MadeYouReset_Tester

GitHubayushghatkar8080/madeyoureset_tester

A Python script that checks if a web server is vulnerable to MadeYouReset (CVE-2025-8671) — an HTTP/2 DoS attack that bypasses Rapid Reset…

exploitationnetwork-securitypenetration-testing+2
42 months ago
Previous12…83Next