Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
git-all-secrets preview

git-all-secrets

GitHubanshumanbh/git-all-secrets

A tool to capture all the git secrets by leveraging multiple open source git searching tools

code-analysisdevsecopsinformation-gathering+1
1.1k
7 years ago
gitoops preview
Archived

gitoops

GitHubovotech/gitoops

all paths lead to clouds

cloud-securitydevsecopsinformation-gathering+6
6402 years ago
RapidWebRecon preview

RapidWebRecon

GitHubadimahluf/rapidwebrecon

A high-performance automation tool designed to bridge the gap between technical web reconnaissance and executive reporting. Developed by **Adi…

devsecopspenetration-testingreconnaissance+2
76 months ago
gato preview
Archived

gato

GitHubpraetorian-inc/gato

GitHub Actions Pipeline Enumeration and Attack Tool

devsecopsexploitationinformation-gathering+7
94 months ago
Dop2Mop preview

Dop2Mop

GitHubh4wkst3r/dop2mop

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

cloud-infrastructure-securitycloud-securitycontainer-security+8
44 months ago
TraceTree preview

TraceTree

GitHubtejasprasad2008-afk/tracetree

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

container-securitydevsecopsdynamic-analysis-sandboxing+6
427 days ago
bumblebee preview

bumblebee

GitHubperplexityai/bumblebee

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

devsecopsincident-responseinformation-gathering+3
5.0k21 days ago
git-hound preview

git-hound

GitHubtillson/git-hound

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

code-analysisdevsecopsinformation-gathering+4
1.5k9 months ago
reposcanner preview

reposcanner

GitHubdionach/reposcanner

Python script to scan Git repos for interesting strings

code-analysisdevsecopsinformation-gathering+1
1606 years ago
faraday_agent_dispatcher preview

faraday_agent_dispatcher

GitHubinfobyte/faraday_agent_dispatcher

Faraday Agent Dispatcher launches any security tools and send results to Faradaysec Platform.

cloud-securitydevsecopsinformation-gathering+5
497 months ago
vexhub preview

vexhub

GitHubaquasecurity/vexhub

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

devsecopsinformation-gatheringsupply-chain-security+2
395 months ago
DiffCatcher preview

DiffCatcher

GitHubteycir/diffcatcher

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

code-analysisdevsecopsinformation-gathering+7
44 months ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubcontrast-security-oss/cve-2021-44228

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

cloud-securitycode-analysisdevsecops+3
3 months ago
noseyparker preview
Archived

noseyparker

GitHubpraetorian-inc/noseyparker

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

code-analysisdevsecopsinformation-gathering+3
2.3k6 months ago
naabu-action preview

naabu-action

GitHubprojectdiscovery/naabu-action

A fast port scanner written in go with a focus on reliability and simplicity.

devsecopsinformation-gatheringnetwork-mapping+3
211 year ago
httpx-action preview

httpx-action

GitHubprojectdiscovery/httpx-action

HTTP Web Server probing

devsecopsinformation-gatheringnetwork-mapping+3
142 years ago
domain-protect preview
Archived

domain-protect

GitHubdomain-protect/domain-protect

OWASP Domain Protect - prevent subdomain takeover

cloud-securitydevsecopsdns-analysis+4
3941 year ago
Leaktopus preview
Archived

Leaktopus

GitHubplaytikaoss/leaktopus

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

code-analysisdevsecopsincident-response+6
305 months ago
Previous12Next