Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
114 results
PacketWhisper preview

PacketWhisper

GitHubtrycatchhcf/packetwhisper

PacketWhisper: Stealthily exfiltrate data and defeat attribution using DNS queries and text-based steganography. Avoid the problems associated with…

cryptographydata-exfiltrationdns-analysis+2
655
6 years ago
ksubdomain preview

ksubdomain

GitHubboy-hack/ksubdomain

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

dns-analysisdns-fuzzingdns-subdomain-enumeration+4
1.2k6 months ago
frogy2.0 preview

frogy2.0

GitHubiamthefrogy/frogy2.0

Orbis is an full spectrum automated external attack surface intelligent toolkit.

cloud-securitydns-analysisemail-security+9
4121 month ago
ngrep preview

ngrep

GitHubjpr5/ngrep

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

dns-analysisforensicsinformation-gathering+3
1.0k7 months ago
r3con1z3r preview

r3con1z3r

GitHubabdulgaphy/r3con1z3r

R3con1z3r is a lightweight Web information gathering tool with an intuitive features written in python. it provides a powerful environment in which…

dns-analysisinformation-gatheringnetwork-mapping+4
2277 years ago
CredPhish preview

CredPhish

GitHubtokyoneon/credphish

PowerShell script that invokes legitimate credential prompts and exfiltrates captured passwords over DNS using CredentialPicker and Resolve-DnsName.

data-exfiltrationdns-analysispassword-attacks+2
2955 years ago
reconerator preview

reconerator

GitHubstufus/reconerator

C# Targeted Attack Reconnissance Tools

dns-analysisinformation-gatheringpost-exploitation+2
1205 years ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5213 days ago
VindicateTool preview

VindicateTool

GitHubrushyo/vindicatetool

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

defensive-toolsdns-analysisincident-response+4
614 years ago
CryptoLyzer preview

CryptoLyzer

GitLabcoroner/cryptolyzer

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

configuration-auditingcryptographydns-analysis+3
2815h 44m ago
FakeNetBIOS preview

FakeNetBIOS

GitHubmubix/fakenetbios

See here:

dns-analysisids-ips-evasionimpersonation-tools+3
4413 years ago
pd-agent preview

pd-agent

GitHubprojectdiscovery/pd-agent

ProjectDiscovery Cloud - Agent

cloud-securitycontainer-securitydns-analysis+6
1522 days ago
shadow-fleet-tracker-light preview

shadow-fleet-tracker-light

GitHubformerlab/shadow-fleet-tracker-light

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

data-exfiltrationdigital-forensicsdns-analysis+9
445 months ago
rosemary preview

rosemary

GitHubblue0x1/rosemary

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

command-and-controldns-analysislateral-movement+4
142 months ago
vaas-cve-2015-5477 preview

vaas-cve-2015-5477

GitHubhmlio/vaas-cve-2015-5477

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

container-securitydns-analysiseducation+3
111 years ago
ecs_checker preview

ecs_checker

GitHubfurkankayapinar/ecs_checker

EDNS Client Subnet (ECS) Remote Detection Tool - CVE-2025-40766

dns-analysisinformation-gatheringnetwork-security+2
11 year ago
CyberCodex preview

CyberCodex

GitHubprox0959/cybercodex

Autonomous 22-Source Zero-Cost OSINT, Data Breach/Leak, Infostealer & Threat Intelligence CLI Engine + Unbiased Cyber Warfare Encyclopedia (11…

data-exfiltrationdigital-forensicsdns-analysis+9
5 days ago
Responder preview
Archived

Responder

GitHubspiderlabs/responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

authenticationdns-analysisexploitation+8
4.9k6 years ago
Previous1234567Next