Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24704 results
trivy preview

trivy

GitHubaquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

cloud-infrastructure-securitycloud-securitycode-analysis+14
38.3k
21h 45m ago
Web-Cache-Vulnerability-Scanner preview

Web-Cache-Vulnerability-Scanner

GitHubhackmanit/web-cache-vulnerability-scanner

Go-based CLI scanner for web cache poisoning and deception. Supports 10 poisoning techniques, multiple deception methods, built-in crawler, JSON…

crawlerpenetration-testingvulnerability-scanners+2
1.2k8 months ago
firmware preview

firmware

GitHubbrucedevices/firmware

Predatory ESP32 Firmware

bluetooth-securityembedded-systems-securityexploitation+9
6.9k28 days ago
ChameleonMini preview

ChameleonMini

GitHubemsec/chameleonmini

The ChameleonMini is a versatile contactless smartcard emulator compliant to NFC. The ChameleonMini was developed by https://kasper-oswald.de. The…

embedded-systems-securityhardware-hackingrfid-nfc-tools+1
1.9k3 years ago
ChameleonMini-rebooted preview

ChameleonMini-rebooted

GitHubiceman1001/chameleonmini-rebooted

Chameleon Mini revE rebooted - Iceman Fork, the ChameleonMini is a versatile contactless smartcard emulator (NFC/RFID)

embedded-systems-securityfirmware-analysishardware-hacking+1
4254 months ago
CVE-2023-38831-RaRCE preview

CVE-2023-38831-RaRCE

GitHubignis-sec/cve-2023-38831-rarce

An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23

exploitationpayload-generationpenetration-testing+2
1133 years ago
NyxInvoke preview

NyxInvoke

GitHubblacksnufkin/nyxinvoke

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

command-and-controlexploitationids-ips-evasion+6
2431 year ago
galah preview

galah

GitHub0x4d31/galah

Galah: An LLM-powered web honeypot.

incident-responseintrusion-detectionthreat-intelligence+1
6701 year ago
tracy preview

tracy

GitHubnccgroup/tracy

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

penetration-testingweb-security
5586 years ago
wfuzz preview

wfuzz

GitHubxmendez/wfuzz

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

fuzzingpenetration-testingvulnerability-analysis+2
6.6k8 months ago
htcap preview

htcap

GitHubfcavallarin/htcap

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

crawlerfuzzingpenetration-testing+2
6294 years ago
WS-Attacker preview

WS-Attacker

GitHubrub-nds/ws-attacker

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University…

fuzzingpenetration-testingvulnerability-analysis+1
4954 years ago
BurpSuiteSharpener preview

BurpSuiteSharpener

GitHubmdsecresearch/burpsuitesharpener

Enhances Burp Suite with tab management, customizable themes, keyboard shortcuts, title renaming, window position memory, and UI utilities for faster…

penetration-testingutilities-frameworksweb-security
5233 years ago
xssmap preview

xssmap

GitHubjewel591/xssmap

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…

penetration-testingvulnerability-analysisweb-security+1
2696 years ago
sessionprobe preview

sessionprobe

GitHubdub-flow/sessionprobe

Multi-threaded web authorization testing tool that evaluates user privileges by checking session token access across a list of URLs, highlighting…

penetration-testingweb-security
4662 years ago
web-brutator preview

web-brutator

GitHubkoutto/web-brutator

Fast Modular Web Interfaces Bruteforcer

password-attackspenetration-testingweb-security
2294 years ago
DDos_Attack.py preview

DDos_Attack.py

GitHubakashblackhat/ddos_attack.py

NetSTRIK is a powerful DDoS (Distributed Denial of Service) attack tool that simulates heavy traffic to test the robustness and security of servers,…

network-securitypenetration-testingweb-security
1711 year ago
reversemap preview

reversemap

GitHubz00nx/reversemap

Analyse SQL injection attempts in web server logs

log-analysisvulnerability-analysisweb-security
829 years ago
Previous12…100Next