Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
55 results
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
25
9 days ago
afrog preview

afrog

GitHubzan8in/afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.

penetration-testingred-teamingvulnerability-scanners+1
4.4k6 days ago
SSTImap preview

SSTImap

GitHubvladko312/sstimap

Automatic SSTI detection tool with interactive interface

code-analysiscommand-and-controldynamic-code-analysis+6
1.7k1 month ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.8k0 days ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.2k9 days ago
WhatWeb preview

WhatWeb

GitHuburbanadventurer/whatweb

Next generation web scanner

crawlerdynamic-code-analysisinformation-gathering+9
6.9k6 months ago
Web-App-PenTesting preview

Web-App-PenTesting

GitHubsarthak4126/web-app-pentesting

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

educationlabs-practicepenetration-testing+4
29 days ago
social-analyzer preview

social-analyzer

GitHubqeeqbox/social-analyzer

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

crawleremail-harvestingimpersonation-tools+7
24.2k8 months ago
mosint preview

mosint

GitHubalpkeskin/mosint

Automated email OSINT tool that verifies emails, checks data breaches and password leaks, finds related emails/domains, scans pastebin dumps, and…

data-exfiltrationemail-harvestinginformation-gathering+2
6.0k3 years ago
kscan preview

kscan

GitHublcvvvv/kscan

Multi-protocol port scanner with fingerprint recognition, service detection, and brute-force authentication testing. Supports 1200+ protocols, 10000+…

network-securitypassword-attacksport-scanning+2
4.3k3 years ago
The-Axer preview

The-Axer

GitHubceh-tn/the-axer

Automated payload generator wrapping msfvenom to streamline creation of platform-specific, encoded, and binded payloads for penetration testing…

exploit-frameworkspayload-developmentpayload-generation+1
988 years ago
Redcloud preview

Redcloud

GitHubkhast3x/redcloud

Automated Red Team Infrastructure deployement using Docker

container-securityexploit-frameworkspenetration-testing-frameworks+1
1.3k4 years ago
jsql-injection preview

jsql-injection

GitHubron190/jsql-injection

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

database-securitypenetration-testingvulnerability-scanners+1
1.8k2 months ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6394 years ago
PRISM-AP preview

PRISM-AP

GitHub1n3/prism-ap

An automated Wireless RogueAP MITM attack framework.

dns-analysisinformation-gatheringpacket-sniffing-analysis+6
1927 years ago
NetExec preview

NetExec

GitHubpennyw0rth/netexec

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

command-and-controldatabase-securityexploitation+14
5.9k12h 29m ago
hackerEnv preview

hackerEnv

GitHubabdulr7mann/hackerenv

Automated penetration testing tool that sweeps IPs, scans ports and vulnerabilities, executes exploits, and provides an interactive shell with…

exploitationinformation-gatheringpenetration-testing+1
4153 years ago
vulnx preview

vulnx

GitHubanouarbensaad/vulnx

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform…

crawlerdns-analysisexploit-frameworks+5
2.1k4 years ago
Previous1234Next