Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Information Gathering | Kitploit
Categories

Information Gathering

General purpose tools for collecting various types of information about targets.

Kitploit recommended

Top tools

10 selected
nmap preview#1

nmap

GitHubnmap/nmap
13.3k1 day ago
amass preview#2

amass

GitHubowasp-amass/amass
15.0k5 months ago
spiderfoot preview#3

spiderfoot

GitHubsmicallef/spiderfoot
20.1k2 years ago
subfinder preview#4

subfinder

GitHubprojectdiscovery/subfinder
14.2k11h 17m ago
theHarvester preview#5

theHarvester

GitHublaramies/theharvester
17.0k4 days ago
reconftw preview#6

reconftw

GitHubsix2dez/reconftw
8.0k1 day ago
httpx preview#7

httpx

GitHubprojectdiscovery/httpx
10.3k12 days ago
WhatWeb preview#8

WhatWeb

GitHuburbanadventurer/whatweb
6.8k5 months ago
naabu preview#9

naabu

GitHubprojectdiscovery/naabu
6.2k2 days ago
FinalRecon preview#10

FinalRecon

GitHubthewhiteh4t/finalrecon
2.9k3 months ago
NewestRelevanceMost popularRecently updated
6161 results
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

privilege-escalationreconnaissancepersistence-mechanisms+8
353 months ago
Cohab_Processes preview

Cohab_Processes

GitHuboctoberfest7/cohab_processes

A small Aggressor script to help Red Teams identify foreign processes on a host machine

scripting-automationinformation-gatheringpost-exploitation+2
893 years ago
aura-inspector preview

aura-inspector

GitHubgoogle/aura-inspector

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

api-security-testinginformation-gatheringweb-security+3
1036 months ago
XSS-Catcher preview

XSS-Catcher

GitHubdaxakahackerman/xss-catcher

A blind XSS detection and XSS data capture framework

vulnerability-scannerspayload-generationweb-application-exploitation+4
17619 days ago
Tylium preview

Tylium

GitHubrandomuserid/tylium

Primary data pipelines for intrusion detection, security analytics and threat hunting

defensive-toolsinformation-gatheringthreat-intelligence+2
854 years ago
Crawlector preview

Crawlector

GitHubmfmokbel/crawlector

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

osintvulnerability-scannersthreat-feeds-aggregators+5
1239 months ago
LEAF preview

LEAF

GitHubalex-cart/leaf

Linux Evidence Acquisition Framework

disk-forensicsioc-managementmemory-forensics+5
1201 year ago
Persistence-Survivability preview

Persistence-Survivability

GitHubkillswitch-gui/persistence-survivability

Powershell Persistence Locator

reconnaissancepersistence-mechanismsinformation-gathering+3
6710 years ago
AIOstack preview

AIOstack

GitHubaurva-io/aiostack

AI runtime inventory: discover shadow AI, trace LLM calls

container-securityinformation-gatheringnetwork-security+8
6220 days ago
proxylogscan preview

proxylogscan

GitHubdwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

reconnaissancevulnerability-scannersexploitation+3
1644 years ago
email-prediction-asterisks preview

email-prediction-asterisks

GitHubquantika14/email-prediction-asterisks

Predicts emails hidden behind asterisks using Intelx leaks for OSINT investigations. Automatically generates a CSV dataset of related emails for…

osintreconnaissanceinformation-gathering+1
733 years ago
troll-a preview

troll-a

GitHubcrissyfield/troll-a

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

vulnerability-analysisinformation-gatheringutilities-frameworks+1
1401 year ago
sccm-http-looter preview

sccm-http-looter

GitHubbadsectorlabs/sccm-http-looter

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

reconnaissancedata-exfiltrationinformation-gathering+3
2171 year ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubbinganao/cve-2024-23897

Proof-of-concept exploit for CVE-2024-23897, a Jenkins arbitrary file read vulnerability, allowing retrieval of sensitive files via crafted HTTP…

vulnerability-analysisexploitationweb-application-exploitation+2
992 years ago
ktr preview

ktr

GitHubhackclub/ktr

Kog traceroute. Highly asynchronous traceroute program written in Rust with ASN WHOIS and PeeringDB lookups.

osintreconnaissancenetwork-mapping+3
17610 months ago
ffufw preview

ffufw

GitHubpuzzlepeaches/ffufw

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

reconnaissanceinformation-gatheringweb-security+2
1466 months ago
BridgeKeeper preview

BridgeKeeper

GitHub0xzdh/bridgekeeper

Scrape, Hunt, and Transform names and usernames

osintreconnaissanceinformation-gathering+2
1303 years ago
KaliIntelligenceSuite preview

KaliIntelligenceSuite

GitHubchopicalqui/kaliintelligencesuite

Automated intelligence-gathering framework that orchestrates Kali Linux tools and public APIs to collect, store, and analyze reconnaissance data for…

osintpenetration-testing-frameworksreconnaissance+3
994 years ago
Previous1…99100Next