Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
592 results
AMFDSer-ngng preview

AMFDSer-ngng

GitHubnccgroup/amfdser-ngng

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
27
11 years ago
reDOM preview

reDOM

GitHubweirdmachine64/redom

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

api-security-testingdynamic-analysis-sandboxinginformation-gathering+5
154 months ago
gitlab-cve-2026-19478-lab preview

gitlab-cve-2026-19478-lab

GitHubdinosn/gitlab-cve-2026-19478-lab

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

api-security-testingexploitationlabs-practice+4
101 month ago
GraphQLGrapper preview

GraphQLGrapper

GitHubm19o/graphqlgrapper

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

api-security-testinginformation-gatheringpenetration-testing+3
211 year ago
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

api-security-testingcrawlerdevsecops+8
1327 days ago
svja preview

svja

GitHubtheronielanddaronpodcastshow/svja

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

api-security-testingauthentication-authorizationeducation+5
139 months ago
Spring-Cloud-Gateway-Nacos preview

Spring-Cloud-Gateway-Nacos

GitHubb0rn2d/spring-cloud-gateway-nacos

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

api-security-testingexploitationpenetration-testing+2
164 years ago
Roxy preview

Roxy

GitHubvid4l-07/roxy

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

api-security-testingpenetration-testingutilities-frameworks+3
614 days ago
Aresius preview

Aresius

GitHub0xmarik/aresius

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

api-security-testingfuzzinginformation-gathering+6
611 days ago
CVE-2026-34910-PoC preview

CVE-2026-34910-PoC

GitHubboreas37/cve-2026-34910-poc

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

api-security-testingauthenticationexploitation+3
71 month ago
Apisix_Crack preview

Apisix_Crack

GitHubyutusec/apisix_crack

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

api-security-testingexploitationmisconfiguration+3
84 years ago
CVE-2018-25031 preview

CVE-2018-25031

GitHubmathis2001/cve-2018-25031

CVE-2018-25031 tests

api-security-testingexploitationphishing-tools+3
34 months ago
CVE-2023-32117 preview

CVE-2023-32117

GitHubrandomrobbiebf/cve-2023-32117

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

api-security-testingexploitationinformation-gathering+3
63 years ago
API-SPY-API-PROBE preview

API-SPY-API-PROBE

GitHubaustinjump-sec/api-spy-api-probe

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

api-security-testingcrawlerinformation-gathering+4
53 months ago
SpEL preview

SpEL

GitHubyutusec/spel

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

api-security-testingexploitationpenetration-testing+3
64 years ago
CVE-2022-22947-Rce_POC preview

CVE-2022-22947-Rce_POC

GitHubhunzi0/cve-2022-22947-rce_poc

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

api-security-testingexploitationpenetration-testing+3
74 years ago
cve-2026-75157-poc preview

cve-2026-75157-poc

GitHublicitrasimone/cve-2026-75157-poc

Standalone authorized universal HTTP PoC for CVE-2026-75157

api-security-testingexploitationpenetration-testing+3
10 days ago
CVE-2026-53625-GLPI-PoC preview

CVE-2026-53625-GLPI-PoC

GitHub7h30th3r0n3/cve-2026-53625-glpi-poc

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

api-security-testingauthentication-authorizationexploitation+4
1 month ago
Previous1…8910…33Next