Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
251 results
FOFA-API-Threaded-Searcher preview

FOFA-API-Threaded-Searcher

GitHubjenderal92/fofa-api-threaded-searcher

Multi‑threaded Python tool to query FOFA API, extract custom fields (IP, port, cert, TLS, etc.), deduplicate results, and resume interrupted searches.

information-gatheringiot-securityosint+1
3 months ago
iptodomain preview

iptodomain

GitHubhackplayers/iptodomain

This tool extract domains from IP address based in the information saved in virustotal.

dns-subdomain-enumerationinformation-gatheringosint+1
239 years ago
awsScrape preview

awsScrape

GitHubjhaddix/awsscrape

A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.

information-gatheringnetwork-mappingnetwork-security+2
2362 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubr4tw1z/cve-2024-6387

This script, created by R4Tw1z, is designed to scan IP addresses to check if they are running a potentially vulnerable version of OpenSSH. The tool…

exploitationinformation-gatheringnetwork-security+3
12 years ago
CF-Hero preview

CF-Hero

GitHubmusana/cf-hero

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

dns-analysisfingerprint-spoofinginformation-gathering+5
2.6k2 months ago
CVE-1999-0524-ICMP-Timestamp-and-Address-Mask-Request-Exploit preview

CVE-1999-0524-ICMP-Timestamp-and-Address-Mask-Request-Exploit

GitHubthreatlabindonesia/cve-1999-0524-icmp-timestamp-and-address-mask-request-exploit

Exploit for CVE-1999-0524 that sends ICMP Timestamp and Address Mask requests to expose network information or trigger denial of service. Supports…

exploitationinformation-gatheringnetwork-security+2
31 year ago
vhostawesome preview

vhostawesome

GitHubxssdoctor/vhostawesome

Concurrent virtual host scanner that brute-forces subdomains across multiple IPs on common web ports, filtering results by status codes and content…

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
372 years ago
PenBox preview

PenBox

GitHubx3omdax/penbox

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

exploitationfuzzinginformation-gathering+8
5369 years ago
inforfinder preview

inforfinder

GitHubggusoft/inforfinder

Inforfinder is a tool to collect information of any domains pointing at some server (ip, domain, range, file). Is able to detect all domains pointing…

dns-subdomain-enumerationinformation-gatheringreconnaissance
671 year ago
Nac_Bypass_Agent preview

Nac_Bypass_Agent

GitHubalperenugurlu/nac_bypass_agent

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

educationids-ips-evasionimpersonation-tools+5
733 years ago
BitLeak preview

BitLeak

GitHubankhcorp/bitleak

Query and display torrent download history linked to a given IP address using public P2P data sources.

information-gatheringosintprivacy
11 year ago
ID-entify preview

ID-entify

GitHubbillyv4/id-entify

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

dns-analysisemail-harvestinginformation-gathering+4
1166 years ago
CVE-2017-8225 preview

CVE-2017-8225

GitHubkienquoc102/cve-2017-8225

Exploit tool for CVE-2017-8225 targeting IP cameras. Scans for vulnerable devices and performs credential brute-forcing to gain unauthorized access.

exploitationinformation-gatheringiot-security+2
24 years ago
Just-Metadata preview

Just-Metadata

GitHubredsiege/just-metadata

Just-Metadata is a tool that gathers and analyzes metadata about IP addresses. It attempts to find relationships between systems within a large…

information-gatheringosintreconnaissance+1
6337 years ago
ipchanger preview

ipchanger

GitHubcappricio-securities/ipchanger

IPChanger is a lightweight command-line tool designed for ethical hackers, security researchers, and privacy enthusiasts. It allows users to…

information-gatheringosintpenetration-testing+2
166 months ago
IPGhost preview

IPGhost

GitLabs_r_e_e_r_a_j/ipghost

IPGhost is a strong tool for ethical hackers. This tool automatically changes your IP address , making it hard for anyone to track your online…

information-gatheringosintprivacy+1
13 months ago
fireprox preview

fireprox

GitHubustayready/fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

api-securitycloud-securityinformation-gathering+5
2.3k4 years ago
subdomain3 preview

subdomain3

GitHubyanxiu0614/subdomain3

A new generation of tool for discovering subdomains( ip , cdn and so on)

dns-subdomain-enumerationinformation-gatheringpenetration-testing+1
7096 years ago
Previous123…14Next