Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
203 results
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

anomaly-detectionanti-botdefensive-tools+11
8.6k
19h 25m ago
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.4k4 days ago
Findomain preview

Findomain

GitHubfindomain/findomain

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

dns-analysisdns-fuzzingdns-subdomain-enumeration+4
3.8k8 days ago
Responder preview

Responder

GitHublgandx/responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

authenticationdns-analysisdns-fuzzing+10
6.6k3 months ago
westone-CVE-2020-14883-scanner preview

westone-CVE-2020-14883-scanner

GitHubosyanina/westone-cve-2020-14883-scanner

A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.

exploitationinformation-gatheringpenetration-testing+2
5 years ago
nmap-CVE-2022-21907 preview

nmap-CVE-2022-21907

GitHubgpiechnik2/nmap-cve-2022-21907

Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution.…

exploitationinformation-gatheringpenetration-testing+2
24 years ago
403bypasser preview

403bypasser

GitHubyunemse48/403bypasser

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

ids-ips-evasioninformation-gatheringpenetration-testing+2
9565 years ago
ipsourcebypass preview

ipsourcebypass

GitHubp0dalirius/ipsourcebypass

This Python script can be used to bypass IP source restrictions using HTTP headers.

information-gatheringpenetration-testingvulnerability-analysis+1
4070 years ago
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
36 days ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
23 days ago
PCredz preview

PCredz

GitHublgandx/pcredz

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

forensicsinformation-gatheringnetwork-security+3
2.6k6 months ago
filebuster preview

filebuster

GitHubhenshin/filebuster

An extremely fast and flexible web fuzzer

fuzzinginformation-gatheringpenetration-testing+1
2233 years ago
crawpy preview

crawpy

GitHubmorph3/crawpy

Asynchronous HTTP content discovery tool with auto-calibration, recursive scanning, and report generation for enumerating hidden web directories and…

crawlerinformation-gatheringreconnaissance+2
1181 year ago
Arecibo preview

Arecibo

GitHubtarlogicsecurity/arecibo

Endpoint for Out-of-Band Exfiltration (DNS & HTTP)

data-exfiltrationdns-analysisinformation-gathering+2
947 years ago
mass3 preview

mass3

GitHubsmiegles/mass3

Multi-threaded DNS-based enumeration tool for discovering AWS S3 buckets using pre-compiled wordlists and custom DNS resolvers, with optional Docker…

cloud-securitydns-analysisinformation-gathering+2
1257 years ago
wsvuls preview

wsvuls

GitHubanouarbensaad/wsvuls

CLI website vulnerability scanner that detects outdated server software, insecure HTTP headers, and extracts Cloudflare IP/port data with performance…

crawlerinformation-gatheringvulnerability-scanners+1
574 years ago
sniffly preview

sniffly

GitHubdiracdeltas/sniffly

Sniffing browser history using HSTS

information-gatheringosintweb-security
9359 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubxmohamed0/cve-2021-41773

Shell-based exploit for CVE-2021-41773 targeting Apache HTTP Server path traversal vulnerability, enabling unauthenticated remote file disclosure and…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
Previous12…12Next