Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
wp2shell-rce preview

wp2shell-rce

GitHubjohnlodan/wp2shell-rce

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

penetration-testingreconnaissancevulnerability-analysis+4
3
21 days ago
WebFEET preview

WebFEET

GitHubnccgroup/webfeet

JavaScript-based enumeration tool for web filtering proxies and policies. Conducts drive-by tests to reveal products, versions, HTTPS inspection…

information-gatheringpenetration-testingreconnaissance+2
7812 years ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubxuemian168/cve-2025-30208

Automated vulnerability scanner for Vite dev servers, detecting CVE-2025-30208, CVE-2025-31125, and CVE-2025-32395 via FOFA or CIDR target collection…

exploitationinformation-gatheringreconnaissance+3
481 year ago
webcopilot preview

webcopilot

GitHubh4r5h1t/webcopilot

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for…

information-gatheringpenetration-testingreconnaissance+3
1.3k2 years ago
CVE-2024-10508 preview

CVE-2024-10508

GitHubjenderal92/cve-2024-10508

Scans WordPress sites for a specific plugin vulnerability (CVE-2024-10508), checks version 6.0.2.6, and saves vulnerable URLs to a file for reporting.

information-gatheringvulnerability-analysisvulnerability-scanners+2
12 months ago
BruteXSS preview
Archived

BruteXSS

GitHubrajeshmajumdar/brutexss

Python-based GUI tool for automated detection of Cross-Site Scripting (XSS) vulnerabilities in web applications using payload injection and response…

information-gatheringpenetration-testingvulnerability-analysis+2
5675 years ago
CVE-2025-0133 preview

CVE-2025-0133

GitHubinteleon404/cve-2025-0133

Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.

exploitationpenetration-testingreconnaissance+3
101 year ago
cgi-printenv preview

cgi-printenv

GitHubcappricio-securities/cgi-printenv

CLI tool to detect CGI printenv information disclosure vulnerability in web servers. Scans single URLs or lists, supports Telegram alerts and output…

information-gatheringmisconfigurationpenetration-testing+3
2 years ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

Automated reconnaissance and vulnerability scanning shell script for bug bounty hunters. Performs passive/active recon, subdomain enumeration, port…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
Zeus-Scanner preview

Zeus-Scanner

GitHubekultek/zeus-scanner

Automated web reconnaissance tool with dork scanning, SQLi/XSS detection, port scanning, admin panel discovery, and WAF/captcha bypass capabilities.

captcha-bypassinformation-gatheringport-scanning+4
9977 years ago
git-scan preview

git-scan

GitHubjenderal92/git-scan

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

information-gatheringmisconfigurationpenetration-testing+1
12 months ago
rapidscan preview

rapidscan

GitHubskavngr/rapidscan

:new: The Multi-Tool Web Vulnerability Scanner.

dns-analysisinformation-gatheringpenetration-testing+5
2.1k3 years ago
recon-ninja preview

recon-ninja

GitHubtess-ss/recon-ninja

Subdomain reconnaissance platform with HTTPX live-host probing, MongoDB-backed storage, searchable UI, and Nuclei vulnerability scanning with Discord…

information-gatheringpenetration-testingreconnaissance+3
882 years ago
livewire-vuln-scanner preview

livewire-vuln-scanner

GitHubjenderal92/livewire-vuln-scanner

Simple scanner to detect vulnerable Livewire installations.

information-gatheringreconnaissancevulnerability-analysis+3
2 months ago
crlfi preview

crlfi

GitHubcappricio-securities/crlfi

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

information-gatheringpenetration-testingvulnerability-analysis+2
52 years ago
barrido preview

barrido

GitLabzer1t0/barrido

Tool to discover paths in web applications

fuzzinginformation-gatheringreconnaissance+2
22 years ago
BlackWidow preview

BlackWidow

GitHub1n3/blackwidow

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

fuzzinginformation-gatheringosint+3
1.8k4 months ago
WSS preview

WSS

GitHubnu11secur1ty/wss

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

code-analysisinformation-gatheringpassword-attacks+3
31 month ago
Previous12345Next