Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1923 results
WPScan preview

WPScan

GitHubalessiodallapiazza/wpscan

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

information-gatheringpenetration-testingreconnaissance+3
31
13 years ago
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

api-security-testingcrawlerdevsecops+8
131 month ago
CVE-2026-23918-Elite-Auditor preview

CVE-2026-23918-Elite-Auditor

GitHubqassam-315/cve-2026-23918-elite-auditor

Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and…

information-gatheringpenetration-testingreconnaissance+3
65 months ago
xpfarm preview

xpfarm

GitHuba3-n/xpfarm

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

ai-securitybinary-analysiseducation+6
445 months ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12613 years ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
1 month ago
changedetection.io preview

changedetection.io

GitHubdgtlmoon/changedetection.io

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

crawlerinformation-gatheringosint+2
34.8k2 days ago
Parsero preview

Parsero

GitHubbehindthefirewalls/parsero

Parsero | Robots.txt audit tool

crawlerinformation-gatheringosint+3
17312 years ago
telegram_bbbot preview
Archived

telegram_bbbot

GitHubmaddevsio/telegram_bbbot

Telegram Bug Bounty Bot

crawlerinformation-gatheringosint+3
329 years ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsinformation-gatheringpenetration-testing+4
11 month ago
phantom-grid preview

phantom-grid

GitHubevkir/phantom-grid

Free Burp Collaborator alternative- OOB interaction capture (HTTP/HTTPS/DNS) with SQLite & exfil reassembly

data-exfiltrationdns-analysisinformation-gathering+7
11 month ago
abdal-cve-2026-60137 preview

abdal-cve-2026-60137

GitHubebrasha/abdal-cve-2026-60137

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection…

information-gatheringpenetration-testingreconnaissance+2
22 months ago
hsecscan preview

hsecscan

GitHubriramar/hsecscan

A security scanner for HTTP response headers.

configuration-auditinginformation-gatheringvulnerability-scanners+1
2981 year ago
wp2shell-Hestia-Scanner preview

wp2shell-Hestia-Scanner

GitHubbytespulse-oe/wp2shell-hestia-scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

ai-securitydefensive-toolsforensics+7
22 months ago
CVE-2025-31324 preview

CVE-2025-31324

GitHubjonathanstross/cve-2025-31324

A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of…

information-gatheringioc-managementpenetration-testing+3
11 year ago
react2shell_detector preview

react2shell_detector

GitHubaliabdollahiii/react2shell_detector

Heuristic security scanner for detecting React Server Components (RSC) vulnerabilities, including React2Shell-style behavior (CVE-2025-55182). Safe,…

information-gatheringpenetration-testingreconnaissance+3
10 months ago
plown preview

plown

GitHubunweb/plown

Security scanner tool for Plone CMS.

information-gatheringpassword-attackspenetration-testing+2
1914 years ago
XXERipper preview

XXERipper

GitHubkamalx06/xxeripper

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

api-security-testingdata-exfiltrationexploitation+9
1114 days ago
Previous12…100Next