Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
nmap preview

nmap

GitHubnmap/nmap

Nmap - the Network Mapper. Github mirror of official SVN repository.

dns-analysisinformation-gatheringnetwork-mapping+7
13.4k6h 59m ago
AutoPWN-Suite preview

AutoPWN-Suite

GitHubgamehunterkaan/autopwn-suite

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

exploitationinformation-gatheringnetwork-security+5
1.1k1 month ago
ghostrecon preview

ghostrecon

GitHubcappricio-securities/ghostrecon

gh0str3con is a All in one cloud based web Recon tool.

crawlerdns-analysisinformation-gathering+5
281 month ago
sippts preview

sippts

GitHubpepelux/sippts

Set of tools to audit SIP based VoIP Systems

exploitationfuzzinginformation-gathering+6
5711 month ago
phantomrecon preview

phantomrecon

GitHubl33tdawg/phantomrecon

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

dns-analysisexploitationinformation-gathering+6
36 months ago
Masscan-Report preview

Masscan-Report

GitHubartofscripting/masscan-report

A Python tool that generates interactive React-based HTML visualizations from masscan JSON output, featuring a D3.js force-directed network graph.

information-gatheringnetwork-mappingport-scanning+1
7 months ago
haxunit preview

haxunit

GitHubbandit-haxunit/haxunit
ai-securitycrawlerfuzzing+7
3321 year ago
CVE-2024-55591-POC preview

CVE-2024-55591-POC

GitHubexfil0/cve-2024-55591-poc

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

authentication-authorizationexploitationnetwork-security+6
121 year ago
Alfred preview
Archived

Alfred

GitHubpwnfuzz/alfred

WIP - Revamped Alfred [2.0]

exploitationinformation-gatheringpenetration-testing+4
401 year ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
GPT_Vuln-analyzer preview

GPT_Vuln-analyzer

GitHubmorpheuslord/gpt_vuln-analyzer

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

ai-securitydns-analysisdns-subdomain-enumeration+7
5961 year ago
Recon preview

Recon

GitHubdirsoooo/recon

Recon is a script to perform a full recon on a target with the main tools to search for vulnerabilities. Created based on @ofjaaah and @Jhaddix…

dns-analysisinformation-gatheringosint+6
2224 years ago
vajra preview
Archived

vajra

GitHubr3curs1v3-pr0xy/vajra

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

crawlerdns-subdomain-enumerationfuzzing+8
7034 years ago
netmap.js preview

netmap.js

GitHubserain/netmap.js

Fast browser-based network discovery module

information-gatheringnetwork-mappingpenetration-testing+2
1155 years ago
rainmap-lite preview

rainmap-lite

GitHubcldrn/rainmap-lite

Rainmap Lite - Responsive web based interface that allows users to launch Nmap scans from their mobiles/tablets/web browsers!

network-mappingport-scanningvulnerability-scanners+1
2345 years ago
WebLogic-SSRF_CVE-2014-4210 preview

WebLogic-SSRF_CVE-2014-4210

GitHubnhpt/weblogic-ssrf_cve-2014-4210

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

exploitationnetwork-mappingport-scanning+3
115 years ago
Excalibur preview

Excalibur

GitHubdviros/excalibur

Excalibur is an Eternalblue exploit payload based "Powershell" for the Bashbunny project.

educationexploitationexploit-frameworks+9
1337 years ago
PortWitness preview

PortWitness

GitHubviperbluff/portwitness

Tool for checking Whether a domain or its multiple sub-domains are up and running.

information-gatheringport-scanningreconnaissance+1
717 years ago
Previous12Next