Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
222 results
kit_hunter preview

kit_hunter

GitHubsteved3/kit_hunter

A basic phishing kit scanner for dedicated and semi-dedicated hosting

malware-analysisphishing-toolsvulnerability-scanners+1
109
3 years ago
wappalyzer-next preview

wappalyzer-next

GitHubs0md3v/wappalyzer-next

detect technologies with wappalyzer alternative

crawlerinformation-gatheringreconnaissance+1
4151 day ago
react preview

react

GitHubjanhalendk/react

A OSINT project that explores how to dump data from React

educationinformation-gatheringosint+2
8211 months ago
GrafXploit preview

GrafXploit

GitHubwezoomagency/grafxploit

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

exploitationinformation-gatheringpenetration-testing+3
41 year ago
Grafxploit preview

Grafxploit

GitHubhxlxmj/grafxploit

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
gotestwaf preview

gotestwaf

GitHubwallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-securityapi-security-testingpenetration-testing+4
1.8k1 year ago
Farmer preview

Farmer

GitHubmdsecactivebreach/farmer
information-gatheringlateral-movementpassword-attacks+4
4275 years ago
private-landing preview

private-landing

GitHubvhscom/private-landing

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

api-securityauthenticationauthentication-authorization+8
793 months ago
https-everywhere preview
Archived

https-everywhere

GitHubefforg/https-everywhere

A browser extension that encrypts your communications with many websites that offer HTTPS but still allow unencrypted connections.

defensive-toolsencryption-decryption-toolsprivacy+1
3.4k3 years ago
caddy preview

caddy

GitHubcaddyserver/caddy

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

encryption-decryption-toolsgeneral-purpose-utilitiesweb-security
75.1k2 days ago
Blacklist3r preview

Blacklist3r

GitHubnotsosecure/blacklist3r

Audits ASP.NET applications for pre-published machine keys to detect ViewState deserialization vulnerabilities and insecure forms authentication…

encryption-decryption-toolspenetration-testingvulnerability-scanners+1
65510 months ago
ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-23457_2-2-3-1
api-securityauthentication-authorizationcode-analysis+6
1 year ago
ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-24891_2-2-3-1
api-securityauthentication-authorizationcode-analysis+5
1 year ago
jetty_9.4.31_CVE-2023-26048 preview

jetty_9.4.31_CVE-2023-26048

GitHubtrinadh465/jetty_9.4.31_cve-2023-26048
general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
2 years ago
jetty_9.4.31_CVE-2021-34428 preview

jetty_9.4.31_CVE-2021-34428

GitHubtrinadh465/jetty_9.4.31_cve-2021-34428
general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
2 years ago
CakeFuzzer preview

CakeFuzzer

GitHubzigrin-security/cakefuzzer

Cake Fuzzer is a project that is meant to help automatically and continuously discover vulnerabilities in web applications created based on specific…

dynamic-analysis-sandboxingfuzzingpenetration-testing+4
1041 year ago
dfir-malware-investigation preview

dfir-malware-investigation

GitHubsuyash-r-k/dfir-malware-investigation

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

digital-forensicseducationincident-response+9
6 months ago
domained preview
Archived

domained

GitHubtypeerror/domained

Multi Tool Subdomain Enumeration

dns-analysisdns-subdomain-enumerationinformation-gathering+5
7235 years ago
Previous12…13Next