#1General purpose tools for collecting various types of information about targets.
Kitploit recommended

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…
A small Aggressor script to help Red Teams identify foreign processes on a host machine

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

A blind XSS detection and XSS data capture framework

Primary data pipelines for intrusion detection, security analytics and threat hunting

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

Linux Evidence Acquisition Framework

Powershell Persistence Locator

AI runtime inventory: discover shadow AI, trace LLM calls

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

Predicts emails hidden behind asterisks using Intelx leaks for OSINT investigations. Automatically generates a CSV dataset of related emails for…

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Proof-of-concept exploit for CVE-2024-23897, a Jenkins arbitrary file read vulnerability, allowing retrieval of sensitive files via crafted HTTP…

Kog traceroute. Highly asynchronous traceroute program written in Rust with ASN WHOIS and PeeringDB lookups.

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

Scrape, Hunt, and Transform names and usernames

Automated intelligence-gathering framework that orchestrates Kali Linux tools and public APIs to collect, store, and analyze reconnaissance data for…