Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
reburp preview

reburp

GitHubforefy/reburp

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

ai-securityapi-security-testingfuzzing+7
1035 days ago
Burp-Recordadora preview

Burp-Recordadora

GitHubhackwarts12/burp-recordadora

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.

penetration-testingutilities-frameworksweb-proxies-interception+1
10 months ago
pentest-pivoting preview

pentest-pivoting

GitHubt3l3machus/pentest-pivoting

A compact guide to network pivoting for penetration testings / CTF challenges.

ctfcurated-resourceseducation+5
2272 years ago
Burp2Malleable preview

Burp2Malleable

GitHubcodextf2/burp2malleable

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

command-and-controlids-ips-evasionpayload-development+2
4193 years ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
burp-awesome-tls preview

burp-awesome-tls

GitHubsleeyax/burp-awesome-tls

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

anti-botfingerprint-spoofingids-ips-evasion+3
1.9k3 days ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k6 months ago
burp-vps-proxy preview

burp-vps-proxy

GitHubd3mondev/burp-vps-proxy

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

penetration-testingutilities-frameworkswaf-bypass+1
2491 year ago
HUNT preview

HUNT

GitHubbugcrowd/hunt

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

curated-resourcespenetration-testingvulnerability-analysis+3
2.3k1 month ago
BurpSuiteSharpenerEx preview

BurpSuiteSharpenerEx

GitHubirsdl/burpsuitesharpenerex

This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.

penetration-testingutilities-frameworksweb-proxies-interception+1
882 months ago
burp2caido preview

burp2caido

GitHubcaido-community/burp2caido

A tool to migrate Burpsuite HTTP history to Caido

penetration-testingutilities-frameworksweb-proxies-interception+1
421 year ago
Jasmin-Ransomware preview

Jasmin-Ransomware

GitHubcodesiddhant/jasmin-ransomware

Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks. Jasmin helps security researchers to…

command-and-controlencryption-decryption-toolsexploitation+5
2875 years ago
BurpSuite-Plugin preview

BurpSuite-Plugin

GitHubjas502n/burpsuite-plugin

Plugin For BurpSuite (Pentester)

penetration-testing-frameworksvulnerability-analysisweb-application-exploitation+2
375 years ago
AutoRepeater preview

AutoRepeater

GitHubnccgroup/autorepeater

Automated HTTP Request Repeating With Burp Suite

api-security-testingauthentication-authorizationpenetration-testing+4
8944 years ago
BurpSuiteHTTPSmuggler preview

BurpSuiteHTTPSmuggler

GitHubnccgroup/burpsuitehttpsmuggler

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

ids-ips-evasionpenetration-testingvulnerability-analysis+3
7447 years ago
Jboss_JMXInvokerServlet_Deserialization_RCE preview

Jboss_JMXInvokerServlet_Deserialization_RCE

GitHubjas502n/jboss_jmxinvokerservlet_deserialization_rce

Jboss_JMXInvokerServlet_Deserialization_RCE

exploitationpayload-generationpenetration-testing+2
217 years ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
116 months ago
HopLa preview

HopLa

GitHubsynacktiv/hopla

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

ai-securityapi-security-testingpayload-generation+3
8375 months ago
Previous12345Next