Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
worldmonitor preview

worldmonitor

GitHubkoala73/worldmonitor

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

ai-securitycrawlerdns-analysis+7
85.5k
7 hours ago
theHarvester preview

theHarvester

GitHublaramies/theharvester

E-mails, subdomains and names Harvester - OSINT

dns-analysisdns-subdomain-enumerationemail-harvesting+9
17.3k22h 41m ago
NetLogic preview

NetLogic

GitHubdmitryflynn/netlogic

NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection

ai-securitycloud-securitydns-analysis+7
14 days ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9687 days ago
InfraGuard preview

InfraGuard

GitHubwhispergate/infraguard

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

anti-botcommand-and-controldns-analysis+8
30912 days ago
kubeshark preview

kubeshark

GitHubkubeshark/kubeshark

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

ai-securitycloud-infrastructure-securitycloud-security+9
12.1k21 days ago
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k1 month ago
Recon-Scan preview

Recon-Scan

GitHubaarocy/recon-scan

Recon-Scan: open‑source passive reconnaissance with AI‑powered security analysis. Zero‑touch, developer‑first, and privacy‑focused.

ai-securitydns-analysisdns-subdomain-enumeration+6
71 month ago
osintnet-public preview

osintnet-public

GitHubosintnet/osintnet-public

OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

ai-securitydigital-forensicsdns-analysis+8
12 months ago
phantomrecon preview

phantomrecon

GitHubl33tdawg/phantomrecon

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

dns-analysisexploitationinformation-gathering+6
36 months ago
GPT_Vuln-analyzer preview

GPT_Vuln-analyzer

GitHubmorpheuslord/gpt_vuln-analyzer

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

ai-securitydns-analysisdns-subdomain-enumeration+7
5971 year ago
proxychains preview

proxychains

GitHubhaad/proxychains

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…

dns-analysisnetwork-securitypenetration-testing+1
7.9k2 years ago
wifipumpkin3 preview

wifipumpkin3

GitHubp0cl4bs/wifipumpkin3

Powerful framework for rogue access point attack.

captcha-bypassdns-analysisphishing+5
2.5k2 years ago
godoh preview

godoh

GitHubsensepost/godoh

🕳 godoh - A DNS-over-HTTPS C2

command-and-controldns-analysispayload-development+1
8082 years ago
Invoke-DNSteal preview

Invoke-DNSteal

GitHubjoelgmsec/invoke-dnsteal

DNS data exfiltrator that sends payloads over UDP/TCP with configurable query size, random delay, and random domains to evade detection during red…

data-exfiltrationdns-analysispenetration-testing+1
1123 years ago
rebindMultiA preview

rebindMultiA

GitHubrhynorater/rebindmultia

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

dns-analysisexploitationpenetration-testing+2
643 years ago
redjoust preview

redjoust

GitHubkawaiipantsu/redjoust

A quick and easy to use security reconnaissance webapp tool, does OSINT, analysis and red-teaming in both passive and active mode. Written in nodeJS…

dns-analysisinformation-gatheringosint+3
304 years ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5344 years ago
Previous12Next