Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
10506 results
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.8k
12 days ago
tcpcopy preview

tcpcopy

GitHubsession-replay-tools/tcpcopy

An online request replication and TCP stream replay tool, ideal for real testing, performance testing, stability testing, stress testing, load…

network-securitypenetration-testingscripting-automation+1
4.7k1 year ago
Rabbit Hole preview

Rabbit Hole

GitLabhostile.node/rabbithole

Lightweight graph-based tool for organizing penetration testing data into visual node-link diagrams of IPs, ports, services, and findings, inspired…

information-gatheringpenetration-testingreconnaissance
36 years ago
CVE-2025-55184_Testing preview

CVE-2025-55184_Testing

GitHubkkhackinglearning/cve-2025-55184_testing

Python script for Testing CVE-2025-55184

exploitationpenetration-testingvulnerability-scanners+2
29 months ago
ReconHound preview

ReconHound

GitLabs_r_e_e_r_a_j/reconhound

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

fuzzinginformation-gatheringpenetration-testing+3
14 months ago
SSHBuster preview

SSHBuster

GitLabs_r_e_e_r_a_j/sshbuster

SSHBuster is a powerful command-line SSH brute-forcing tool designed for ethical hacking and penetration testing. It performs dictionary-based…

password-attackspenetration-testing
14 months ago
PHP-REVERSE-SHELL preview

PHP-REVERSE-SHELL

GitLabs_r_e_e_r_a_j/php-reverse-shell

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

command-and-controleducationids-ips-evasion+6
10 years ago
keyhacks preview

keyhacks

GitHubstreaak/keyhacks

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

api-securitypenetration-testingsecret-detection+1
6.3k1 month ago
testssl.sh preview

testssl.sh

GitHubtestssl/testssl.sh

Testing TLS/SSL encryption anywhere on any port

cryptographynetwork-securitypenetration-testing+2
9.2k15h 38m ago
wfuzz preview

wfuzz

GitHubxmendez/wfuzz

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

fuzzingpenetration-testingvulnerability-analysis+2
6.6k7 months ago
w3af preview

w3af

GitHubandresriancho/w3af

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

exploitationpenetration-testingvulnerability-scanners+3
4.9k6 years ago
HUNT preview

HUNT

GitHubbugcrowd/hunt

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

curated-resourcespenetration-testingvulnerability-analysis+3
2.3k22 days ago
sysreptor preview

sysreptor

GitHubsyslifters/sysreptor

A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your…

penetration-testingutilities-frameworks
2.6k22h 18m ago
exploits preview

exploits

GitHubr4j0x00/exploits

Proof-of-concept exploit collection targeting Linux kernel LPE, sudo heap overflow, and Chrome V8 OOB write vulnerabilities for penetration testing.

binary-exploitationexploitationpenetration-testing+2
2.5k3 years ago
bloodyAD preview

bloodyAD

GitHubcravaterouge/bloodyad

LDAP-based Active Directory privilege escalation framework supporting pass-the-hash, pass-the-ticket, and certificate authentication for automated…

authenticationexploitationpenetration-testing+1
2.3k2 days ago
Inveigh preview

Inveigh

GitHubkevin-robertson/inveigh

.NET IPv4/IPv6 machine-in-the-middle tool for penetration testers

penetration-testingred-teaming
3.0k10 months ago
smuggler preview

smuggler

GitHubdefparam/smuggler

Python-based HTTP request smuggling and desync testing tool that detects CL.TE and TE.CL vulnerabilities using configurable mutation payloads and…

penetration-testingvulnerability-scannersweb-application-exploitation+1
2.1k5 years ago
PowerTools preview

PowerTools

GitHubpowershellempire/powertools

Collection of offensive PowerShell projects for reconnaissance, privilege escalation, and post-exploitation during penetration testing engagements.

penetration-testingpost-exploitationprivilege-escalation+1
2.2k9 years ago
Previous12…100Next