Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
Scanner-and-Patcher preview

Scanner-and-Patcher

GitHubmalwareman007/scanner-and-patcher

A Web Vulnerability Scanner and Patcher

dns-subdomain-enumerationeducationexploitation+8
173
1 year ago
Argus preview

Argus

GitHubdozermx/argus

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

api-securityfuzzinginformation-gathering+9
56 months ago
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

api-securityapi-security-testingdynamic-code-analysis+14
5.6k2 days ago
RED_HAWK preview

RED_HAWK

GitHubtuhinshubhra/red_hawk

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

crawlerdns-analysisinformation-gathering+5
3.8k6 years ago
AutoPWN-Suite preview

AutoPWN-Suite

GitHubgamehunterkaan/autopwn-suite

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

exploitationinformation-gatheringnetwork-security+5
1.1k6 days ago
rengine preview

rengine

GitHubyogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

crawlerdns-subdomain-enumerationinformation-gathering+9
8.9k10 months ago
ATSCAN preview

ATSCAN

GitHubalisamtechnology/atscan

Advanced dork Search & Mass Exploit Scanner

crawlerdns-subdomain-enumerationemail-harvesting+7
1.6k2 years ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
nmap preview

nmap

GitHubnmap/nmap

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

bluetooth-securitydatabase-securitydata-exfiltration+18
13.7k1 day ago
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.4k23 days ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
xerosploit preview

xerosploit

GitHublionsec/xerosploit

Efficient and advanced man in the middle framework

exploitationinformation-gatheringnetwork-security+4
2.2k3 years ago
vulnx preview

vulnx

GitHubanouarbensaad/vulnx

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform…

crawlerdns-analysisexploit-frameworks+5
2.1k4 years ago
killshot preview

killshot

GitHubbahaabdelwahed/killshot

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

exploit-frameworksfuzzinginformation-gathering+6
78710 months ago
LogMePwn preview

LogMePwn

GitHub0xinfection/logmepwn

A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.

exploitationfuzzingnetwork-mapping+3
3952 months ago
BlackDir-Framework preview

BlackDir-Framework

GitHubjehadalqurashi/blackdir-framework

Web Application Vulnerability Scanner

encryption-decryption-toolshash-analysisinformation-gathering+5
1376 years ago
pentest-mcp preview

pentest-mcp

GitHubdmontgomery40/pentest-mcp

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

exploitationfuzzingnetwork-mapping+8
1476 months ago
KUMO-Domain-Recon-Tool preview

KUMO-Domain-Recon-Tool

GitHubkarim852/kumo-domain-recon-tool

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

dns-analysisinformation-gatheringosint+8
598 days ago
Previous1234Next