Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Pentest-Bookmarkz — A collection of useful links for Pentesters | Kitploit
Tools/GitHubGitHub/sofianehamlaoui/pentest-bookmarkz
OSINT (Open Source Intelligence)Password CrackingExploitationReverse EngineeringWeb SecurityCTFPenetration TestingLearning & EducationRed TeamingCurated ResourcesLearning Paths & CoursesLabs & Practice
18046191 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubsofianehamlaoui/pentest-bookmarkz

Pentest-Bookmarkz

A collection of useful links for Pentesters

View RepositoryWebsite

Pentest Bookmarks List Sofiane Hamlaoui

Check more on Google : https://g.co/kgs/FUZgoXi

Hacker Media

Blogs

There are a LOT of pentesting blogs, these are the ones I monitor constantly and value in the actual day to day testing work.

  • Carnal 0wnage - atom
  • McGrew Security
  • GNUCITIZEN
  • Darknet - The Darkside - rss
  • spylogic - rss
  • TaoSecurity - atom
  • Room362
  • SIPVicious - rss
  • portswigger
  • pentestmonkeyblog
  • jeremiahgrossman
  • i8jesus
  • c22
  • Skull Security - rss
  • metasploit
  • darkoperator
  • skeptikal
  • preachsecurity
  • tssci-security
  • gdssecurityl
  • websec
  • bernardodamele
  • laramies
  • andlabs
  • xs-sniperblog
  • commonexploits
  • sensepostblog
  • wepma
  • Exploit KB - rss
  • securityreliks
  • Mad Irish - rss
  • sirdarckcat
  • reusablesec
  • myne-us
  • notsosecure
  • spiderlabs
  • corelan
  • DigiNinja - rss
  • pauldotcom
  • attackvector
  • deviating
  • alphaonelabs
  • smashingpasswords
  • wirewatcher
  • gynvael
  • nullthreat
  • question-defense
  • archangelamael
  • memset
  • sickness
  • punter-infosec
  • securityninja
  • securityandrisk
  • pentestit

Forums:

Created for forums that will help in both tool usage, syntax, attack techniques, and collection of scripts and tools.

  • EH-Net Forums
  • Hak5 Forums
  • Kali Linux Forums
  • Hack Forums
  • Hackthissite Forums
  • Security Override Forums
  • Government Security

Wikis

  • Pwn Wiki
  • Skull Security
  • BlindSeeker Wiki
  • SQL Injection Wiki
  • Forgotten Security's CTF Wiki

Magazines:

  • (In)Secure Magazine
  • Hackin9

Video:

  • SecurityTube

Methodologies:

  • Penetration Testing Framework
  • The Penetration Testing Execution Standard
  • The WASC Threat Classification
  • OWASP Top Ten Project
  • The Social Engineering Framework

OSINT

People and Organizational:

  • http://www.spokeo.com/
  • http://www.123people.com/
  • http://www.xing.com/
  • http://www.zoominfo.com/search
  • http://pipl.com/
  • http://www.zabasearch.com/
  • http://www.searchbug.com/default.aspx
  • http://theultimates.com/
  • http://skipease.com/
  • http://addictomatic.com/
  • http://socialmention.com/
  • http://entitycube.research.microsoft.com/
  • http://www.yasni.com/
  • http://tweepz.com/
  • http://tweepsearch.com/
  • http://www.glassdoor.com/index.htm
  • http://www.jigsaw.com/
  • http://searchwww.sec.gov/EDGARFSClient/jsp/EDGAR_MainAccess.jsp
  • http://www.tineye.com/
  • http://www.peekyou.com/
  • http://picfog.com/
  • http://twapperkeeper.com/index.php

Infrastructure:

  • http://uptime.netcraft.com/
  • http://www.serversniff.net/
  • http://www.domaintools.com/
  • http://centralops.net/co/
  • http://hackerfantastic.com/
  • http://whois.webhosting.info/
  • https://www.ssllabs.com/ssldb/analyze.html
  • http://www.clez.net/
  • http://www.my-ip-neighbors.com/
  • https://www.shodan.io/
  • http://www.exploit-db.com/google-dorks/
  • http://www.hackersforcharity.org/ghdb/

Exploits and Advisories:

  • http://www.exploit-db.com/
  • http://www.cvedetails.com/
  • https://cxsecurity.com/
  • http://www.packetstormsecurity.org/
  • http://www.securityforest.com/wiki/index.php/Main_Page
  • http://www.securityfocus.com/bid
  • http://nvd.nist.gov/
  • http://osvdb.org/
  • http://www.nullbyte.org.il/Index.html
  • http://secdocs.lonerunners.net/
  • http://www.phenoelit-us.org/whatSAP/index.html
  • http://secunia.com/
  • http://cve.mitre.org/

Cheatsheets and Syntax:

  • http://cirt.net/ports_dl.php?export=services
  • http://www.cheat-sheets.org/
  • http://blog.securitymonks.com/2009/08/15/whats-in-your-folder-security-cheat-sheets/

Agile Hacking:

  • http://www.gnucitizen.org/blog/agile-hacking-a-homegrown-telnet-based-portscanner/
  • http://blog.commandlinekungfu.com/
  • http://www.securityaegis.com/simple-yet-effective-directory-bruteforcing/
  • http://isc.sans.edu/diary.html?storyid=2376
  • http://isc.sans.edu/diary.html?storyid=1229
  • http://ss64.com/nt/
  • http://pauldotcom.com/2010/02/running-a-command-on-every-mac.html
  • http://synjunkie.blogspot.com/2008/03/command-line-ninjitsu.html
  • http://www.zonbi.org/2010/06/09/wmic-the-other-other-white-meat/
  • http://rstcenter.com/forum/22324-hacking-without-tools-windows.rst
  • http://www.coresecurity.com/files/attachments/Core_Define_and_Win_Cmd_Line.pdf
  • http://www.scribd.com/Penetration-Testing-Ninjitsu2-Infrastructure-and-Netcat-without-Netcat/d/3064507
  • http://www.pentesterscripting.com/
  • http://www.sans.org/reading_room/whitepapers/hackers/windows-script-host-hack-windows_33583
  • http://www.blackhat.com/presentations/bh-dc-10/Bannedit/BlackHat-DC-2010-Bannedit-Advanced-Command-Injection-Exploitation-1-wp.pdf

OS and Scripts:

Download Tool