Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
omnisci3nt preview

omnisci3nt

GitHubspyboy-productions/omnisci3nt

Omnisci3nt is an open-source web reconnaissance and intelligence tool for extracting deep technical insights from domains, including subdomains, SSL…

dns-analysisinformation-gatheringosint+6
370
3 months ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
bettercap preview

bettercap

GitHubbettercap/bettercap

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

bluetooth-securitydata-exfiltrationfingerprint-spoofing+16
20.0k1 month ago
wireshark preview

wireshark

GitHubwireshark/wireshark

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

bluetooth-securitydata-exfiltrationdigital-forensics+11
9.9k8h 57m ago
ethr preview

ethr

GitHubmicrosoft/ethr

Cross-platform CLI for network performance testing over TCP, UDP, HTTP, HTTPS, and ICMP: bandwidth, connections/s, packets/s, latency, loss, jitter,…

data-exfiltrationgeneral-purpose-utilitiesinformation-gathering+3
5.9k9 months ago
CallStranger preview

CallStranger

GitHubyunuscadirci/callstranger

Vulnerability checker for Callstranger (CVE-2020-12695)

data-exfiltrationdns-analysisiot-security+3
4035 years ago
voidsec-proxy preview

voidsec-proxy

GitHubvoidsecsoftwares/voidsec-proxy

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…

data-exfiltrationdigital-forensicsdns-subdomain-enumeration+8
423 days ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
13 months ago
xray preview
Archived

xray

GitHubevilsocket/xray

XRay is a tool for recon, mapping and OSINT gathering from public networks.

dns-analysisdns-subdomain-enumerationinformation-gathering+5
2.3k2 years ago
Gorsair preview
Archived

Gorsair

GitHubullaakut/gorsair

Gorsair gives root access on remote docker containers that expose their APIs

cloud-securitycontainer-securityexploitation+6
8472 years ago
CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner preview

CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner

GitHubcyberdudebivash/cyberdudebivash-fortisiem-cve-2025-64155-scanner

Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and…

command-and-controlexploitationpenetration-testing+3
18 months ago
web-check preview

web-check

GitHublissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

dns-analysisemail-harvestinginformation-gathering+10
35.0k3h 43m ago
sonar preview

sonar

GitHubraskrebs/sonar

CLI tool for inspecting and managing services listening on localhost ports

devsecopsgeneral-purpose-utilitiesinformation-gathering+3
1.1k11 days ago
kimi preview

kimi

GitHubalechilczenko/kimi

Attack Surface Discovery tool built on a microservice approach, utilizing multi-threading for fast, internet-scale asset indexing

educationinformation-gatheringiot-security+3
2619 months ago
ivre preview

ivre

GitHubivre/ivre

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive…

dns-analysisinformation-gatheringnetwork-mapping+4
4.2k22 days ago
Masscan-Report preview

Masscan-Report

GitHubartofscripting/masscan-report

A Python tool that generates interactive React-based HTML visualizations from masscan JSON output, featuring a D3.js force-directed network graph.

information-gatheringnetwork-mappingport-scanning+1
8 months ago
Dome preview

Dome

GitHubv4d1/dome

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

dns-analysisosintpenetration-testing+3
5452 years ago
Blind-SSRF-CVE-2020-15002 preview

Blind-SSRF-CVE-2020-15002

GitHubskr0x1c0/blind-ssrf-cve-2020-15002

https://hackerone.com/reports/865652

exploitationport-scanningreconnaissance+2
5 years ago
Previous12Next