Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k
2 months ago
PolarDNS preview

PolarDNS

GitHuboryxlabs/polardns

PolarDNS is a specialized authoritative DNS server suitable for penetration testing and vulnerability research.

dns-analysisfuzzingnetwork-security+3
2521 year ago
DNSrecon-gui preview

DNSrecon-gui

GitHubmicro-joan/dnsrecon-gui

Graphical DNS enumeration tool for Kali Linux that scans standard records (A, NS, SOA, MX) and visualizes results in mind maps for reconnaissance and…

dns-analysisdns-subdomain-enumerationinformation-gathering+2
633 years ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
1 month ago
SiteBroker preview
Archived

SiteBroker

GitHubanon-exploiter/sitebroker

A cross-platform python based utility for information gathering and penetration testing automation!

crawlerdns-analysisinformation-gathering+5
4302 years ago
PCAPdroid preview

PCAPdroid

GitHubemanuele-f/pcapdroid

No-root network monitor, firewall and PCAP dumper for Android

android-securitydns-analysiseducation+8
4.9k12 days ago
Olyx preview

Olyx

GitLabshacode/olyx

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

android-securityapi-securitydns-analysis+7
8 months ago
bromite preview

bromite

GitHubbromite/bromite

Android Chromium fork with built-in ad blocking, anti-fingerprinting mitigations, DNS-over-HTTPS, and hardened privacy and security defaults.

android-securityanti-botdefensive-tools+7
6.3k2 years ago
bypass-firewalls-by-DNS-history preview

bypass-firewalls-by-DNS-history

GitHubvincentcox/bypass-firewalls-by-dns-history

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

dns-analysispenetration-testingreconnaissance+2
1.3k6 years ago
subjack preview

subjack

GitHubhaccer/subjack

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

dns-analysispenetration-testingsubdomain-enumeration+2
2.1k6 months ago
Spoofy preview

Spoofy

GitHubmattkeeley/spoofy

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

dns-analysisemail-securitypenetration-testing+1
77510 days ago
tko-subs preview

tko-subs

GitHubanshumanbh/tko-subs

A tool that can help detect and takeover subdomains with dead DNS records

cloud-securitydns-analysispenetration-testing+2
7735 years ago
log4shell-tools preview

log4shell-tools

GitHubalexbakker/log4shell-tools

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

dns-analysisexploitationpenetration-testing+3
862 years ago
rebindMultiA preview

rebindMultiA

GitHubrhynorater/rebindmultia

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

dns-analysisexploitationpenetration-testing+2
643 years ago
CVE-2020-1350 preview

CVE-2020-1350

GitHubcaptaingeech42/cve-2020-1350

Proof-of-concept Denial of Service exploit for CVE-2020-1350 (SIGRed) targeting Windows DNS servers via crafted DNS SIG records. Includes PCAP for…

dns-analysisexploitationpenetration-testing+2
186 years ago
CVE-2020-1350 preview

CVE-2020-1350

GitHubmr-r3b00t/cve-2020-1350

PowerShell script to mitigate CVE-2020-1350 (SigRED) by reducing DNS server TCP receive packet size limit and restarting the service.

dns-analysisexploitationnetwork-security+3
46 years ago
ams-failopen preview

ams-failopen

GitHubjgoyd/ams-failopen

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…

dns-analysisexploitationpenetration-testing+3
31 year ago
CVE-2017-3143 preview

CVE-2017-3143

GitHubsaaph/cve-2017-3143

Exploit for TSIG bypass vulnerabilities in Bind (CVE-2017-3143) and Knot DNS (CVE-2017-11104)

dns-analysisexploitationnetwork-security+2
17 years ago
Previous1234Next