Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
awesome-search-queries preview

awesome-search-queries

GitHubprojectdiscovery/awesome-search-queries

Community curated list of search queries for various products across multiple search engines.

curated-resourcesdns-subdomain-enumerationeducation+5
405
4h 1m ago
wordlists preview

wordlists

GitHubtrickest/wordlists

Infosec wordlists for content discovery, directory brute-force, and subdomain enumeration: CMS/technology paths, robots.txt disallowed paths, and SSL…

curated-resourcesinformation-gatheringpenetration-testing+3
1.8k2 days ago
resolvers preview

resolvers

GitHubtrickest/resolvers

Curated, continuously validated list of reliable DNS resolvers for DNS enumeration, reconnaissance, and bug bounty workflows.

curated-resourcesdns-analysisdns-subdomain-enumeration+6
1.0k3 days ago
bug-bounty-library preview

bug-bounty-library

GitLabwattocyber/bug-bounty-library

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and…

curated-resourceseducationfuzzing+6
4 days ago
awesome-web-security preview

awesome-web-security

GitHubqazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

ctfcurated-resourceseducation+7
13.7k4 days ago
Burp-Suite-Certified-Practitioner-Exam-Study preview

Burp-Suite-Certified-Practitioner-Exam-Study

GitHubbotesjuan/burp-suite-certified-practitioner-exam-study

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

curated-resourceseducationinformation-gathering+7
1.5k6 days ago
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.2k7 days ago
maswe preview

maswe

GitHubowasp/maswe

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

android-securitycurated-resourceseducation+4
408 days ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.4k16 days ago
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k26 days ago
KingOfBugBountyTips preview

KingOfBugBountyTips

GitHubkingofbugbounty/kingofbugbountytips

Curated bug bounty reconnaissance methodology with 400+ one-liners for subdomain enumeration, vulnerability scanning, API testing, and OSINT.…

curated-resourceseducationosint+5
5.5k1 month ago
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

cloud-securitycurated-resourceseducation+8
352 months ago
Active-Directory-Exploitation-Cheat-Sheet preview

Active-Directory-Exploitation-Cheat-Sheet

GitHubs1ckb0y1337/active-directory-exploitation-cheat-sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

curated-resourceseducationexploitation+5
6.7k3 months ago
goodoldsearch-oss preview

goodoldsearch-oss

GitHubmrtdlgc/goodoldsearch-oss

Local static query builder for precise search across web engines, Shodan, crt.sh, and Wayback Machine. Supports Google dorks, filetype filters, date…

curated-resourcesdns-subdomain-enumerationeducation+6
213 months ago
WhoCord preview

WhoCord

GitHubsiv-nick/whocord

Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…

curated-resourcesdns-subdomain-enumerationeducation+8
843 months ago
research preview

research

GitHubalessandrobertoldi/research

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

authenticationcurated-resourcesdns-subdomain-enumeration+5
3 months ago
cwe-tool preview

cwe-tool

GitHubowasp/cwe-tool

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

code-analysiscurated-resourceseducation+3
643 months ago
cwe-sdk-javascript preview

cwe-sdk-javascript

GitHubowasp/cwe-sdk-javascript

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

code-analysiscurated-resourceseducation+3
323 months ago
Previous12Next