Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
597 results
domains-from-csp preview

domains-from-csp

GitHub0xbharath/domains-from-csp

A script to extract domain names from Content Security Policy(CSP) headers

dns-analysisinformation-gatheringnetwork-mapping+5
113
7 years ago
probequest preview

probequest

GitHubskyplabs/probequest

Toolkit for Playing with Wi-Fi Probe Requests

information-gatheringosintpacket-sniffing-analysis+3
2819 months ago
Leaktopus preview
Archived

Leaktopus

GitHubplaytikaoss/leaktopus

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

code-analysisdevsecopsincident-response+6
295 months ago
Awesome-Hacking-Resources preview

Awesome-Hacking-Resources

GitHubvitalysim/awesome-hacking-resources

A collection of hacking / penetration testing resources to make you better!

ai-securityctfcurated-resources+9
17.4k3 months ago
tangalanga preview

tangalanga

GitHubelcuervo/tangalanga

Tangalanga: the Zoom conference scanner hacking tool

information-gatheringosintreconnaissance+1
2895 years ago
SourceWolf preview

SourceWolf

GitHubksharinarayanan/sourcewolf

Amazingly fast response crawler to find juicy stuff in the source code! 😎🔥

crawlerfuzzinginformation-gathering+3
1572 years ago
InfoHound preview

InfoHound

GitHubfundacio-i2cat/infohound

InfoHound is an OSINT to extract a large amount of data given a web domain name.

dns-analysiseducationemail-harvesting+8
1632 years ago
waybackpack preview

waybackpack

GitHubjsvine/waybackpack

Download the entire Wayback Machine archive for a given URL.

information-gatheringosintutilities-frameworks+1
3.2k1 year ago
sdwan-harvester preview

sdwan-harvester

GitHubsdnewhop/sdwan-harvester

🌐 Automatically enumerate and fingerprint SD-WAN nodes on the internet

information-gatheringnetwork-mappingosint+4
495 years ago
SharpHound3 preview
Archived

SharpHound3

GitHubbloodhoundad/sharphound3

C# Data Collector for the BloodHound Project, Version 3

information-gatheringosintpenetration-testing+2
5574 years ago
SnafflerParser preview

SnafflerParser

GitHubzh54321/snafflerparser

Parses Snaffler output file and generate beautified outputs.

data-exfiltrationinformation-gatheringlog-analysis+5
1503 months ago
GoMapEnum preview

GoMapEnum

GitHubnodauf/gomapenum

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

cloud-securityemail-harvestinginformation-gathering+4
49411 months ago
m365_groups_enum preview

m365_groups_enum

GitHubcnotin/m365_groups_enum

Enumerate Microsoft 365 Groups in a tenant with their metadata

cloud-securityinformation-gatheringosint+1
555 years ago
MSOLSpray preview

MSOLSpray

GitHubdafthack/msolspray

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a…

authenticationcloud-securityinformation-gathering+3
1.1k3 years ago
SOC-L1-OSINT-Investigation-MikroTik-CVE-2018-1156 preview

SOC-L1-OSINT-Investigation-MikroTik-CVE-2018-1156

GitHubjonathaninfinity01/soc-l1-osint-investigation-mikrotik-cve-2018-1156

L1 SOC Analysis: OSINT detection and risk validation of publicly exposed MikroTik RouterOS vulnerable to RCE | Tools: Shodan, NIST NVD

educationincident-responseinformation-gathering+6
3 months ago
CVE-2017-5487 preview

CVE-2017-5487

GitHubdream434/cve-2017-5487

Exploit for CVE-2017-5487 to enumerate WordPress user accounts via the REST API, extracting sensitive information from vulnerable 4.7 installations.

information-gatheringosintreconnaissance+2
1 year ago
TwitWork preview

TwitWork

GitHubatmoner/twitwork

✨ Monitor twitter stream from nodejs electron

crawlerinformation-gatheringosint
2765 years ago
guardian-cli preview

guardian-cli

GitHubzakirkun/guardian-cli

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

ai-securitycloud-securityeducation+8
1.9k2 months ago
Previous1…151617…34Next