Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
dnstake preview

dnstake

GitHubpwnesia/dnstake

Fast DNS takeover scanner that checks for missing hosted zones by querying nameservers and fingerprinting providers to identify vulnerable subdomains.

dns-analysisinformation-gatheringsubdomain-enumeration+1
856
4 years ago
mx-takeover preview

mx-takeover

GitHubmusana/mx-takeover

Scans DNS MX records to detect misconfigured, expiring, or unregistered domains vulnerable to email takeover, with automatic reclamation support for…

dns-analysisemail-securitymisconfiguration+1
3603 years ago
webstor preview

webstor

GitHubrossgeerlings/webstor

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

dns-analysisinformation-gatheringreconnaissance+2
1572 years ago
log4jcheck preview

log4jcheck

GitHubnorthwavesecurity/log4jcheck

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

dns-analysisexploitationinformation-gathering+3
1274 years ago
SpoofcheckSelfTest preview

SpoofcheckSelfTest

GitHubbishopfox/spoofcheckselftest

Web application that lets you test if your domain is vulnerable to email spoofing

configuration-auditingdns-analysisemail-security+1
447 years ago
log4shell-cloud-scanner preview

log4shell-cloud-scanner

GitHubmitiga/log4shell-cloud-scanner

we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in…

cloud-infrastructure-securitycloud-securitydns-analysis+3
144 years ago
cve-2020-13777 preview

cve-2020-13777

GitHub0xxon/cve-2020-13777

Zeek script to detect servers vulnerable to CVE-2020-13777

dns-analysisintrusion-detectionnetwork-security+2
411 months ago
aiohttp-exploit-CVE-2024-23334-certstream preview

aiohttp-exploit-CVE-2024-23334-certstream

GitHubsxyrxyy/aiohttp-exploit-cve-2024-23334-certstream

Automated exploit tool for CVE-2024-23334 that collects domains from certstream, checks for vulnerable Python aiohttp servers, and sends successful…

dns-analysisexploitationinformation-gathering+3
42 years ago
CVE-2023-43323 preview

CVE-2023-43323

GitHubahrixia/cve-2023-43323

mooSocial v3.1.8 is vulnerable to external service interaction on post function.

dns-analysisexploitationinformation-gathering+2
12 years ago
CVE-2025-5688-FreeRTOS-Plus-TCP-Out-of-Bounds-Write preview

CVE-2025-5688-FreeRTOS-Plus-TCP-Out-of-Bounds-Write

GitHubmbanyamer/cve-2025-5688-freertos-plus-tcp-out-of-bounds-write

PoC exploit for CVE-2025-5688: remote out-of-bounds write in FreeRTOS-Plus-TCP via crafted LLMNR/mDNS queries, causing crash or potential RCE on…

binary-exploitationdns-analysisembedded-systems-security+6
6 months ago
dns_amplification_scanner preview

dns_amplification_scanner

GitHubpcastagnaro/dns_amplification_scanner

This script checks if each domain from a given domain list is vulnerable to CVE-2006-0987

dns-analysisinformation-gatheringnetwork-security+3
11 year ago
CVE-2023-50387 preview

CVE-2023-50387

GitHubpablodiz/cve-2023-50387

DNS vulnerability exploit for CVE-2023-50387 with automated RRSIG key generation and Docker-based attack simulation against vulnerable and patched…

dns-analysiseducationexploitation+3
1 year ago
log4j preview

log4j

GitHubhassaanahmad813/log4j

Multithreaded Python scanner that detects Log4Shell (CVE-2021-44228) by sending crafted HTTP requests with JNDI payloads and monitoring DNS callbacks…

dns-analysisexploitationinformation-gathering+2
4 years ago
CVE-2020-1350 preview
Archived

CVE-2020-1350

GitHubt13nn3s/cve-2020-1350

This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service

dns-analysisexploitationpenetration-testing+2
153 years ago
log4j-scan preview

log4j-scan

GitHubfullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

dns-analysisexploitationvulnerability-scanners+2
3.4k3 years ago
NSE-scripts preview

NSE-scripts

GitHubpsc4re/nse-scripts

NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473

dns-analysisexploitationinformation-gathering+5
1625 years ago
cve-2015-5477 preview

cve-2015-5477

GitHubrobertdavidgraham/cve-2015-5477

PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure

dns-analysisexploitationpenetration-testing+1
6411 years ago
tkeypoc preview

tkeypoc

GitHubelceef/tkeypoc

PoC exploit code for CVE-2015-5477 BIND9 TKEY remote DoS vulnerability

dns-analysisexploitationpenetration-testing+1
1411 years ago
Previous12Next