Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
50 results
dnsgen preview

dnsgen

GitHubalephnullsk/dnsgen

Generates domain name permutations for subdomain enumeration and recon, supporting custom wordlists, cloud patterns, and fast mode for security…

dns-analysisdns-fuzzingdns-subdomain-enumeration+5
1.1k
1 year ago
Dnsplit preview

Dnsplit

GitHubk3ystr0k3r/dnsplit

Fast subdomain enumeration tool written in python.

dns-subdomain-enumerationinformation-gatheringpenetration-testing+2
57 months ago
Wordell preview

Wordell

GitHubk3ystr0k3r/wordell

Wordell is a powerful WordPress enumeration script designed to make your WordPress security assessments more efficient and comprehensive. It enables…

information-gatheringosintpenetration-testing+3
43 years ago
PS2 preview

PS2

GitHubnccgroup/ps2

A port scanner written purely in PowerShell.

information-gatheringnetwork-mappingnetwork-security+3
822 years ago
Search_CVE preview

Search_CVE

GitHubk3ystr0k3r/search_cve

ntroducing Search_CVE: Unleash the Power of CVE Searching Search_CVE is a cutting-edge tool designed to simplify and optimize the process of…

information-gatheringreconnaissancethreat-intelligence+1
33 months ago
airecon preview

airecon

GitHubpikpikcu/airecon

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

ai-securityeducationexploitation+6
9714 months ago
ProHunter preview

ProHunter

GitHubxueboqiu/prohunter

Graph-based threat detection system using inexact graph vector matching to compare threat graphs with CTI-derived attack query graphs for automated…

anomaly-detectioninformation-gatheringmachine-learning+3
118 months ago
urlfinder preview

urlfinder

GitHubprojectdiscovery/urlfinder

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

crawlerdns-subdomain-enumerationinformation-gathering+5
90221h 58m ago
AD-Attack-Defense preview

AD-Attack-Defense

GitHubinfosecn1nja/ad-attack-defense

Attack and defend active directory using modern post exploitation adversary tradecraft activity

curated-resourcesdefensive-toolseducation+7
4.9k1 year ago
RSC-Detect-CVE-2025-55182 preview

RSC-Detect-CVE-2025-55182

GitHubvijay-shirhatti/rsc-detect-cve-2025-55182

RSC Detect CVE 2025 55182

curated-resourceseducationinformation-gathering+3
218 months ago
Metasploit-Exploits-CVE-2023-6710 preview

Metasploit-Exploits-CVE-2023-6710

GitHubdedsec-47/metasploit-exploits-cve-2023-6710

Welcome to the Metasploit Exploits Repository, your go-to resource for a comprehensive collection of cutting-edge exploits designed for penetration…

educationexploit-frameworkspayload-development+4
12 years ago
CVE-2022-39986-RaspAP-2.8.0-2.8.7-RCE preview

CVE-2022-39986-RaspAP-2.8.0-2.8.7-RCE

GitHubmind2hex/cve-2022-39986-raspap-2.8.0-2.8.7-rce

bash script for automated discovery and exploitation of machines with the CVE-2022-39986 vulnerability

educationexploitationinformation-gathering+3
2 years ago
Onionscan preview

Onionscan

GitLabn3ph0s/onionscan

Scan and analyze Tor hidden services (.onion) to extract metadata, SSH banners, email addresses, and potential IP leaks via mod_status, with a…

crawlerdns-analysisemail-harvesting+4
4 years ago
CVE-2025-68645 preview

CVE-2025-68645

GitHubcrow5-oss/cve-2025-68645

Proof-of-Concept scanner for CVE-2025-68645, detecting Local File Inclusion (LFI) in Zimbra Collaboration Suite via the /h/printcalendar endpoint…

exploitationinformation-gatheringpenetration-testing+3
6 months ago
GHunt preview

GHunt

GitHubmxrch/ghunt

Async offensive Google framework for OSINT, enabling email/Gaia ID/Drive/geolocation reconnaissance via CLI or Python library with JSON export.

email-harvestinginformation-gatheringosint+4
19.4k4 months ago
Photon preview

Photon

GitHubs0md3v/photon

Incredibly fast crawler designed for OSINT.

crawlerdns-subdomain-enumerationemail-harvesting+5
13.1k19 days ago
woocommerce_scanner preview

woocommerce_scanner

GitHubtdawg506/woocommerce_scanner

A Python script designed to scan a list of WordPress sites to identify those with WooCommerce installed and check if they are vulnerable to…

information-gatheringreconnaissancevulnerability-scanners+1
11 months ago
reconswarm preview

reconswarm

GitHubrenatus-cartesius/reconswarm

Extend your recon with cloud power

cloud-securitydevsecopspenetration-testing+2
95 months ago
Previous123Next