Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
431 results
Memcrashed-DDoS-Exploit preview

Memcrashed-DDoS-Exploit

GitHub649/memcrashed-ddos-exploit

DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API

exploitationinformation-gatheringosint
1.4k6 years ago
yasuo preview

yasuo

GitHub0xsauby/yasuo

A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network

exploitationinformation-gatheringpenetration-testing+2
5748 years ago
Silver preview

Silver

GitHubs0md3v/silver

Mass scan IPs for vulnerable services

information-gatheringnetwork-securityreconnaissance+1
1.1k4 months ago
HostileSubBruteforcer preview

HostileSubBruteforcer

GitHubnahamsec/hostilesubbruteforcer

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

cloud-securitydns-subdomain-enumerationinformation-gathering+3
4829 years ago
dnstake preview

dnstake

GitHubpwnesia/dnstake

Fast DNS takeover scanner that checks for missing hosted zones by querying nameservers and fingerprinting providers to identify vulnerable subdomains.

dns-analysisinformation-gatheringsubdomain-enumeration+1
8564 years ago
CVE-2024-6387_Check preview

CVE-2024-6387_Check

GitHubxaitax/cve-2024-6387_check

CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH

exploitationinformation-gatheringnetwork-security+3
5283 months ago
dorkScanner preview

dorkScanner

GitHubmadhavmehndiratta/dorkscanner

A typical search engine dork scanner scrapes search engines with dorks that you provide in order to find vulnerable URLs.

information-gatheringosintvulnerability-scanners+1
2863 years ago
kerberoast preview

kerberoast

GitHubskelsec/kerberoast

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

authenticationexploitationinformation-gathering+2
4342 years ago
php_filter_chains_oracle_exploit preview

php_filter_chains_oracle_exploit

GitHubsynacktiv/php_filter_chains_oracle_exploit

A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.

exploitationinformation-gatheringpenetration-testing+2
3342 years ago
DorkNet preview

DorkNet

GitHubnullarray/dorknet

Selenium powered Python script to automate searching for vulnerable web apps.

information-gatheringosintvulnerability-scanners+1
3496 years ago
AdbNet preview

AdbNet

GitHub0x1ca3/adbnet

A tool that allows you to search for vulnerable android devices across the world and exploit them.

android-securityexploitationinformation-gathering+4
4345 years ago
Parth preview

Parth

GitHubs0md3v/parth

Heuristic Vulnerable Parameter Scanner

information-gatheringpenetration-testingreconnaissance+2
6034 years ago
reconness preview

reconness

GitHubreconness/reconness

Automated continuous reconnaissance platform that orchestrates a pipeline of recon tools via scheduled or event-driven triggers, helping security…

information-gatheringpenetration-testingreconnaissance
3273 years ago
white-deface preview

white-deface

GitHubwhxitte/white-deface

This is a simple python tool to automatically deface webdav vulnerable websites.

exploitationinformation-gatheringpenetration-testing+1
1771 year ago
FireShodanMap preview

FireShodanMap

GitHubwarflop/fireshodanmap

FireShodanMap is a Realtime map that integrates Firebase, Google Maps and Shodan. A search is carried out using Shodan searching vulnerable devices…

information-gatheringosintreconnaissance+1
1258 years ago
dorkscout preview

dorkscout

GitHubr4ygm/dorkscout

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

crawlerinformation-gatheringosint+2
2435 years ago
nextssrf preview

nextssrf

GitHubynsmroztas/nextssrf

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

cloud-securityexploitationinformation-gathering+3
773 months ago
webstor preview

webstor

GitHubrossgeerlings/webstor

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

dns-analysisinformation-gatheringreconnaissance+2
1572 years ago
Previous12…24Next