Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
BWASP preview

BWASP

GitHubbwasp/bwasp

BoB Web Application Security Project

educationpenetration-testingvulnerability-analysis+3
2239 months ago
CVE-2024-10508 preview

CVE-2024-10508

GitHubjenderal92/cve-2024-10508

This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific…

information-gatheringvulnerability-analysisvulnerability-scanners+2
13 months ago
crlfi-scanner preview

crlfi-scanner

GitHubcappricio-securities/crlfi-scanner

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

fuzzingpenetration-testingweb-application-exploitation+2
46 months ago
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.3k2 days ago
Optiva-Framework preview

Optiva-Framework

GitHubjoker25000/optiva-framework

Optiva-Framework 🔎 Web Application Scanner🕵️

encryption-decryption-toolshash-analysisinformation-gathering+6
3148 years ago
goWAPT preview

goWAPT

GitHubdzonerzy/gowapt

Go Web Application Penetration Test

fuzzingpenetration-testingscripting-automation+4
3452 years ago
OSTE-Meta-Scan preview

OSTE-Meta-Scan

GitHubostesayed/oste-meta-scan

Multi-engine DAST scanner aggregating Nikto, ZAP, Nuclei, SkipFish, and Wapiti for automated web injection vulnerability detection with consolidated…

dynamic-analysis-sandboxingeducationpenetration-testing+3
3041 year ago
BlackDir-Framework preview

BlackDir-Framework

GitHubjehadalqurashi/blackdir-framework

Web Application Vulnerability Scanner

encryption-decryption-toolshash-analysisinformation-gathering+5
1375 years ago
XSpear preview
Archived

XSpear

GitHubhahwul/xspear

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

dynamic-analysis-sandboxingfuzzinginformation-gathering+8
1.4k6 months ago
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

api-securityapi-security-testingcrawler+12
38.5k17h 39m ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.1k13 days ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.6k5 months ago
vulmap preview

vulmap

GitHubzhzyker/vulmap

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

exploitationpenetration-testingvulnerability-analysis+1
3.5k4 years ago
kiterunner preview

kiterunner

GitHubassetnote/kiterunner

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

api-securityapi-security-testingdynamic-code-analysis+5
3.3k5 years ago
killshot preview

killshot

GitHubbahaabdelwahed/killshot

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

exploit-frameworksfuzzinginformation-gathering+6
7849 months ago
webcopilot preview

webcopilot

GitHubh4r5h1t/webcopilot

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for…

information-gatheringpenetration-testingreconnaissance+3
1.3k2 years ago
graphw00f preview

graphw00f

GitHubdolevf/graphw00f

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

api-securityapi-security-testingdynamic-code-analysis+5
9004 months ago
kaboom preview

kaboom

GitHubleviathan36/kaboom

A tool to automate penetration tests

exploit-frameworksinformation-gatheringpassword-attacks+4
3825 years ago
Previous123Next