Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
APT-GUID — APT-GUID | Kitploit
Tools/GitHubGitHub/al1ex/apt-guid
OSINT (Open Source Intelligence)Privilege EscalationVulnerability AnalysisExploitationInformation GatheringPost-ExploitationCommand and ControlSocial EngineeringLearning & EducationRed TeamingCurated Resources
2312175 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
al1ex/apt-guid

APT-GUID

APT-GUID

View Repository

Project Introduction

Organizing materials in the APT field, covering but not limited to the following aspects

  • APT attack tools

  • APT analysis reports

  • APT attack techniques

Tool Collection

Information Gathering

Active Intelligence Gathering
  • EyeWitness can take screenshots of websites, provide some server information, and identify default credentials where possible https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump a tool for quickly enumerating AWS S3 Buckets to look for loot https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE is a tool for performing information gathering on domains https://github.com/michenriksen/aquatone
  • Spoofcheck, used to check whether a domain can be spoofed; the program checks SPF and DMARC records for weak configurations that allow spoofing https://github.com/BishopFox/spoofcheck
  • Nmap used to discover hosts and services on a computer network https://github.com/nmap/nmap
  • dnsrecon is a DNS enumeration script https://github.com/darkoperator/dnsrecon
  • dirsearch is a simple command-line tool to brute-force website directories https://github.com/maurosoria/dirsearch
  • Sn1per is an automated penetration testing tool https://github.com/1N3/Sn1per
Passive Intelligence Gathering
  • Social Mapper OSINT social media mapping tool that takes a list of usernames and images (or LinkedIn company names) and performs large-scale automated target searches across multiple social media sites. Not limited by APIs because it uses Selenium. https://github.com/SpiderLabs/social_mapper
  • skiptracer OSINT exploitation framework https://github.com/xillwillx/skiptracer
  • FOCA mainly used to find metadata and hidden information in scanned documents. https://github.com/ElevenPaths/FOCA
  • theHarvester used to collect subdomains, email addresses, virtual hosts, ports/banners, and employee names from different public sources. https://github.com/laramies/theHarvester
  • Metagoofil is a tool for extracting metadata from public documents (pdf, doc, xls, ppt, etc.) available on target websites. https://github.com/laramies/metagoofil
  • SimplyEmail email reconnaissance. https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog searches git repositories for sensitive data, digging deep into commit history and branches. https://github.com/dxa4481/truffleHog
  • Just-Metadata a tool for collecting and analyzing metadata about IP addresses. It tries to find relationships between systems in large datasets. https://github.com/ChrisTruncer/Just-Metadata
  • typofinder shows the country/region where an IP address is located. https://github.com/nccgroup/typofinder
  • pwnedOrNot is a python script that checks whether an email account has been compromised in a data breach; if the email account has been compromised, it continues to find passwords for that account. https://github.com/thewhiteh4t/pwnedOrNot
  • GitHarvester this tool is used to gather information from GitHub, such as google dorks. https://github.com/metac0rtex/GitHarvester
  • pwndb is a python command-line tool used to search for leaked credentials using the Onion service of the same name. https://github.com/davidtavarez/pwndb/
  • LinkedInt LinkedIn Recon tool. https://github.com/vysecurity/LinkedInt
  • CrossLinked LinkedIn enumeration tool that extracts valid employee names from organizations by scraping search engines. https://github.com/m8r0wn/CrossLinked
  • findomain fast subdomain enumeration tool that uses certificate transparency logs and some APIs. https://github.com/Edu4rdSHL/findomain

Exploitation

Download Tool