Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
wappalyzer-next preview

wappalyzer-next

GitHubs0md3v/wappalyzer-next

detect technologies with wappalyzer alternative

crawlerinformation-gatheringreconnaissance+1
41816h 45m ago
pwned preview

pwned

GitHubwkovacs64/pwned

CLI tool to query the Have I Been Pwned API for breached accounts, pastes, and password exposure, enabling rapid security assessment of compromised…

information-gatheringosintpassword-cracking+1
2461 day ago
ipatool preview

ipatool

GitHubmajd/ipatool

Command-line tool that allows you to search for iOS, iPadOS, tvOS, visionOS, and macOS apps on the App Store, and download .ipa or macOS .pkg app…

information-gatheringios-securitymobile-app-pentesting+2
11.5k1 day ago
WP2Shell-Scanner preview

WP2Shell-Scanner

GitHubsec-dan/wp2shell-scanner

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

information-gatheringpenetration-testingreconnaissance+3
1 month ago
CVE-2026-4631-cockpit-RCE preview

CVE-2026-4631-cockpit-RCE

GitHubexdev994/cve-2026-4631-cockpit-rce

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

command-and-controlexploitationinformation-gathering+6
2 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubrix4uni/cve-2025-55182

A command-line tool for detecting CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server Components.

command-and-controlexploitationinformation-gathering+4
64 months ago
FTPBuster preview

FTPBuster

GitLabs_r_e_e_r_a_j/ftpbuster

FTPBuster is a powerful command-line brute-forcing tool designed to brute-force FTP, SFTP, and explicit FTPS servers by performing dictionary-based…

information-gatheringpassword-attackspenetration-testing
15 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
36 months ago
pspy preview

pspy

GitHubdominicbreuker/pspy

Monitor linux processes without root permissions

ctfinformation-gatheringpenetration-testing+2
6.2k7 months ago
rapiddns-cli preview

rapiddns-cli

GitHubrapiddns/rapiddns-cli

A powerful command-line interface for interacting with the [RapidDNS API](https://rapiddns.io/help/api). This tool allows you to perform DNS…

dns-analysisdns-subdomain-enumerationinformation-gathering+3
417 months ago
xsubfind3r preview

xsubfind3r

GitHubhueristiq/xsubfind3r

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

dns-subdomain-enumerationinformation-gatheringosint+2
11910 months ago
xurlfind3r preview

xurlfind3r

GitHubhueristiq/xurlfind3r

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

information-gatheringosintpenetration-testing+2
72410 months ago
jsleak preview

jsleak

GitHubbyt3hx/jsleak

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

information-gatheringreconnaissancesecret-detection+1
5961 year ago
TLDHunt preview

TLDHunt

GitHubyuyudhn/tldhunt

Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

dns-subdomain-enumerationinformation-gatheringosint+2
1851 year ago
NextSploit preview

NextSploit

GitHubanonkryptiquz/nextsploit

NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js

authenticationexploitationinformation-gathering+3
911 year ago
NextJS-Exploit- preview

NextJS-Exploit-

GitHubpixilated730/nextjs-exploit-

CVE-2025-29927

educationexploitationinformation-gathering+3
11 year ago
crlfi preview

crlfi

GitHubcappricio-securities/crlfi

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

information-gatheringpenetration-testingvulnerability-analysis+2
72 years ago
FuegoTest preview

FuegoTest

GitHub0zer0d4y/fuegotest

A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.

configuration-auditingexploitationinformation-gathering+3
2 years ago
Previous12Next