Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
117 results
XnlReveal preview

XnlReveal

GitHubxnl-h4ck3r/xnlreveal

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

information-gatheringosintpenetration-testing+3
453
5 months ago
OmniSec-Hex preview

OmniSec-Hex

GitHubvighnesh91/omnisec-hex

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

ai-securitybinary-analysisfuzzing+9
215 days ago
legion preview
Archived

legion

GitHubabacus-group-rto/legion

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

container-securityexploitationids-ips-evasion+8
1.1k1 year ago
Sitadel preview

Sitadel

GitHubshenril/sitadel

Web Application Security Scanner

information-gatheringpenetration-testingvulnerability-scanners+3
6117h 57m ago
vedas-signatures preview

vedas-signatures

GitHubarpsyndicate/vedas-signatures

VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 12000 CVEs

curated-resourcesdefensive-toolsintrusion-detection+8
191 day ago
rengine preview

rengine

GitHubyogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

crawlerdns-subdomain-enumerationinformation-gathering+9
8.9k10 months ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
ronin preview

ronin

GitHubronin-rb/ronin

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

cryptographyctfdns-analysis+9
7628 months ago
SecurityManageFramwork preview

SecurityManageFramwork

GitHubwe1h0/securitymanageframwork

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management,…

configuration-auditingnetwork-mappingpassword-cracking+4
4316 years ago
bxss preview

bxss

GitHubethicalhackingplayground/bxss

Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.

information-gatheringpenetration-testingvulnerability-scanners+2
4201 year ago
CVE-2025-24813-Scanner preview

CVE-2025-24813-Scanner

GitHubmattb709/cve-2025-24813-scanner

CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file…

exploitationinformation-gatheringpenetration-testing+3
51 year ago
crlfi preview

crlfi

GitHubcappricio-securities/crlfi

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

information-gatheringpenetration-testingvulnerability-analysis+2
72 years ago
CVE-2025-31324 preview

CVE-2025-31324

GitHubrxerium/cve-2025-31324

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially…

exploitationinformation-gatheringpenetration-testing+3
411 months ago
git-scan preview

git-scan

GitHubjenderal92/git-scan

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

information-gatheringmisconfigurationpenetration-testing+1
14 months ago
CVE-2024-25202 preview

CVE-2024-25202

GitHubagampreet-singh/cve-2024-25202

A vulnerability was found in PHPgurukul visitor management system 1.0. it has been rated as problemic. Affected by the issue is some unknown…

exploitationinformation-gatheringpenetration-testing+3
12 years ago
CVE-2024-12084 preview

CVE-2024-12084

GitHubrxerium/cve-2024-12084

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths…

exploitationinformation-gatheringpenetration-testing+3
111 months ago
phpinfo-files-leaks preview

phpinfo-files-leaks

GitHubcappricio-securities/phpinfo-files-leaks

This tool is used to find php info page

information-gatheringmisconfigurationpenetration-testing+4
12 years ago
laravel-ignition-Rxss preview

laravel-ignition-Rxss

GitHubcappricio-securities/laravel-ignition-rxss

Laravel Ignition contains a cross-site scripting vulnerability when debug mode is enabled.

penetration-testingreconnaissancevulnerability-scanners+2
2 years ago
Previous1234567Next