Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
55 results
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.2k
15h 33m ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

api-security-testingdevsecopsdynamic-analysis-sandboxing+5
15.7k2 days ago
Sitadel preview

Sitadel

GitHubshenril/sitadel

Web Application Security Scanner

information-gatheringpenetration-testingvulnerability-scanners+3
6132 days ago
pyfiscan preview

pyfiscan

GitHubfgeek/pyfiscan

Free web-application vulnerability and version scanner

information-gatheringvulnerability-scannersweb-security+1
57514 days ago
crlf-powered-desync-scanner preview

crlf-powered-desync-scanner

GitHubt0xodile/crlf-powered-desync-scanner
exploitationpenetration-testingweb-application-exploitation+2
171 month ago
web-penetration-drupal preview

web-penetration-drupal

GitHuberman-bolukbasi/web-penetration-drupal

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

exploit-frameworkspenetration-testingreconnaissance+3
1 month ago
jaeles preview

jaeles

GitHubjaeles-project/jaeles

The Swiss Army knife for automated Web Application Testing

penetration-testingvulnerability-scannersweb-security+1
2.4k2 months ago
Wordpress-Default-Password preview

Wordpress-Default-Password

GitHubjenderal92/wordpress-default-password

python 2.7

password-attackspenetration-testingweb-security+1
2 months ago
Clickjacking-Exploit-Detector preview

Clickjacking-Exploit-Detector

GitHubjenderal92/clickjacking-exploit-detector

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.

penetration-testingweb-application-exploitationweb-security+1
32 months ago
Vehicle-Service-Management-System-Mechanic-List-Stored-Cross-Site-Scripting-XSS preview

Vehicle-Service-Management-System-Mechanic-List-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/vehicle-service-management-system-mechanic-list-stored-cross-site-scripting-xss

CVE-2021-46069 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List Section in…

exploitationpenetration-testingvulnerability-analysis+3
3 months ago
Vehicle-Service-Management-System-Service-List-Stored-Cross-Site-Scripting-XSS preview

Vehicle-Service-Management-System-Service-List-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/vehicle-service-management-system-service-list-stored-cross-site-scripting-xss

CVE-2021-46072 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in…

exploitationpenetration-testingvulnerability-analysis+3
13 months ago
Vehicle-Service-Management-System-Settings-Stored-Cross-Site-Scripting-XSS preview

Vehicle-Service-Management-System-Settings-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/vehicle-service-management-system-settings-stored-cross-site-scripting-xss

CVE-2021-46074 - A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings…

exploitationpenetration-testingvulnerability-analysis+2
3 months ago
arachni preview
Archived

arachni

GitHubarachni/arachni

Web Application Security Scanner Framework

crawlerdynamic-analysis-sandboxingpenetration-testing+3
4.0k4 months ago
BlackWidow preview

BlackWidow

GitHub1n3/blackwidow

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

fuzzinginformation-gatheringosint+3
1.8k4 months ago
Pegasus-Pentest-Arsenal preview

Pegasus-Pentest-Arsenal

GitHubsobri3195/pegasus-pentest-arsenal

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

api-security-testingctfeducation+9
554 months ago
crlfi-scanner preview

crlfi-scanner

GitHubcappricio-securities/crlfi-scanner

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

fuzzingpenetration-testingweb-application-exploitation+2
45 months ago
Scanner-and-Patcher preview

Scanner-and-Patcher

GitHubmalwareman007/scanner-and-patcher

A Web Vulnerability Scanner and Patcher

dns-subdomain-enumerationeducationexploitation+8
1746 months ago
BWASP preview

BWASP

GitHubbwasp/bwasp

BoB Web Application Security Project

educationpenetration-testingvulnerability-analysis+3
2238 months ago
Previous1234Next