Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
119 results
scada-scanner preview

scada-scanner

GitHubgeeknik/scada-scanner

A high-performance, asynchronous SCADA/ICS scanner

information-gatheringnetwork-mappingnetwork-security+6
16
8 months ago
fsociety preview

fsociety

GitHubmanisso/fsociety

Modular penetration testing framework bundling 40+ tools for information gathering, password attacks, exploitation, web hacking, sniffing, and…

exploitationinformation-gatheringpassword-attacks+6
12.3k1 month ago
singularity preview

singularity

GitHubnccgroup/singularity

DNS rebinding attack framework with custom DNS/HTTP servers, automated port scanning, and payload delivery for exploiting internal network services…

dns-analysisexploitationinformation-gathering+6
1.3k1 month ago
BugBountyScanner preview

BugBountyScanner

GitHubchvancooten/bugbountyscanner

A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.

crawlerinformation-gatheringpenetration-testing+5
9229 months ago
CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner preview

CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner

GitHubbkfish/cnvd-2020-10487-tomcat-ajp-lfi-scanner

Multithreaded scanner for CVE-2020-1938 (Tomcat AJP LFI) that first identifies hosts with port 8009 open, then tests for the vulnerability and…

exploitationinformation-gatheringpenetration-testing+3
2944 years ago
Spartan preview

Spartan

GitHubmad-robot/spartan

Automated reconnaissance framework integrating subdomain enumeration, live host probing, port scanning, CMS detection, and directory brute-forcing…

information-gatheringpenetration-testingport-scanning+3
1935 years ago
Recon preview

Recon

GitHubdirsoooo/recon

Automated reconnaissance script for bug bounty and pentesting, integrating subdomain enumeration, port scanning, directory fuzzing, WAF detection,…

dns-analysisinformation-gatheringosint+6
2224 years ago
PCWT preview

PCWT

GitHubascr0b/pcwt

Web-based project management interface for penetration testing and bug bounty workflows, automating port scanning with Nmap/Masscan and subdomain…

information-gatheringpenetration-testingpenetration-testing-frameworks+5
465 years ago
radar preview

radar

GitHubdeade1e/radar

High-performance network scanner in Rust for asynchronous TCP/UDP/ARP scanning with rate limiting, JSON output, and a hackable console mode for…

information-gatheringnetwork-mappingpacket-sniffing-analysis+3
47 months ago
opensshenum preview

opensshenum

GitHubgbonacini/opensshenum

CVE-2018-15473-based OpenSSH user enumerator with port scanning, fingerprinting, and parallel execution for verifying user presence on remote SSH…

exploitationinformation-gatheringnetwork-security+3
37 years ago
C-Port-Scanner preview

C-Port-Scanner

GitHubneutralwarrior/c-port-scanner

A port scanner that scans a target IP for open ports and displays the results, built with C

information-gatheringnetwork-mappingpenetration-testing+2
25 months ago
CVE-2020-0688-Scanner preview

CVE-2020-0688-Scanner

GitHubslsteff/cve-2020-0688-scanner

Scans IP ranges with masscan to identify Microsoft Exchange servers and versions, checking for CVE-2020-0688 vulnerability via OWA logon page and ECP…

information-gatheringnetwork-mappingport-scanning+3
25 years ago
BOF_Collection preview

BOF_Collection

GitHubrvrsh3ll/bof_collection

Cobalt Strike BOFs for in-memory post-exploitation: Active Directory enumeration, clipboard capture, WiFi credential dump, port scan, and registry…

command-and-controlinformation-gatheringpersistence-mechanisms+4
7853 years ago
jfscan preview
Archived

jfscan

GitHubnullt3r/jfscan

JF⚡can - Super fast port scanning & service discovery using Masscan and Nmap. Scan large networks with Masscan and use Nmap's scripting abilities to…

information-gatheringnetwork-mappingpenetration-testing+3
6706 months ago
nray preview

nray

GitHubnray-scanner/nray

Distributed port and application layer scanner for multi-vantage-point network reconnaissance. Supports event-based result streaming, cross-platform…

information-gatheringnetwork-mappingnetwork-security+3
1581 year ago
Alfred preview
Archived

Alfred

GitHubpwnfuzz/alfred

Modular Python framework for automated reconnaissance, exploitation, and post-exploitation tasks with NLP-driven plugin execution and extensible…

exploitationinformation-gatheringpenetration-testing+4
401 year ago
inter-recon preview

inter-recon

GitHubinternon/inter-recon

Script to perform automatic initial web and vulnerability recon

dns-analysisfuzzinginformation-gathering+7
84 years ago
freshonions-torscraper preview

freshonions-torscraper

GitHubdirtyfilthy/freshonions-torscraper

Fresh Onions is an open source TOR spider / hidden service onion crawler hosted at zlal32teyptf4tvi.onion

crawlerinformation-gatheringnetwork-mapping+4
5396 years ago
Previous1234567Next