Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
235 results
spiderfoot preview

spiderfoot

GitHubsmicallef/spiderfoot

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

dns-analysisemail-harvestinginformation-gathering+9
21.8k
2 years ago
graphw00f preview

graphw00f

GitHubdolevf/graphw00f

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

api-securityapi-security-testingdynamic-code-analysis+5
8983 months ago
CVE-2026-0300 preview

CVE-2026-0300

GitHubshizuku198411/cve-2026-0300

Non-destructive exposure survey tool for assessing PAN-OS User-ID Authentication Portal surfaces related to CVE-2026-0300, performing safe HTTP(S)…

defensive-toolsinformation-gatheringnetwork-security+3
14 months ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
8 days ago
ladder preview

ladder

GitHubeverywall/ladder

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

anti-botapi-securityweb-proxies-interception+1
8.9k1 month ago
LavaDome preview

LavaDome

GitHublavamoat/lavadome

Secure DOM trees isolation and encapsulation leveraging ShadowDOM

defensive-toolsprivacyweb-security
361 year ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

api-securitycloud-securitydefensive-tools+5
1.6k3 days ago
cve-2026-1731-scanner preview

cve-2026-1731-scanner

GitHubcybrdude/cve-2026-1731-scanner

Passive vulnerability scanner for CVE-2026-1731 — BeyondTrust RS/PRA pre-auth RCE (CVSS 9.9). Educational & defensive use only.

defensive-toolseducationinformation-gathering+5
46 months ago
mimicry preview

mimicry

GitHubchaitin/mimicry

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

defensive-toolsincident-responsered-teaming+1
625 months ago
pollyscan preview

pollyscan

GitHubpadayali-jd/pollyscan

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…

misconfigurationsupply-chain-securitythreat-intelligence+2
61 year ago
lua-resty-limit-traffic preview

lua-resty-limit-traffic

GitHubopenresty/lua-resty-limit-traffic

Lua library for limiting and controlling traffic in OpenResty/ngx_lua

anti-botdefensive-toolsgeneral-purpose-utilities+1
85413 days ago
safetext preview

safetext

GitHubgoogle/safetext

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

defensive-toolsdevsecopsscripting-automation+1
1515 months ago
shellsum preview

shellsum

GitHubmanhnho/shellsum

A defense tool - detect web shells in local directories via md5sum

defensive-toolsmalware-analysisvulnerability-scanners+1
327 years ago
chrome-vuln-scanner preview

chrome-vuln-scanner

GitHubvirologi-info/chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

defensive-toolseducationstatic-analysis+2
8 days ago
NginxHunter preview

NginxHunter

GitHubemrekybs/nginxhunter

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…

defensive-toolsincident-responselog-analysis+2
52 years ago
CVE-2025-55182-scanner preview

CVE-2025-55182-scanner

GitHubyaupunal/cve-2025-55182-scanner

CVE-2025-55182-scanner with 2 different method

defensive-toolsids-ips-evasionmisconfiguration+3
9 months ago
globaleaks-whistleblowing-software preview

globaleaks-whistleblowing-software

GitHubglobaleaks/globaleaks-whistleblowing-software

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

defensive-toolsencryption-decryption-toolsprivacy+1
1.5k1 day ago
owasp-java-encoder preview

owasp-java-encoder

GitHubowasp/owasp-java-encoder

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

code-analysisdefensive-toolsencryption-decryption-tools+3
5419 months ago
Previous12…14Next