Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
skytrack preview

skytrack

GitHubang13t/skytrack

Command-line aircraft OSINT tool for gathering tail numbers, ICAO codes, flight logs, and owner details from public aviation data sources, with PDF…

information-gatheringosintreconnaissance
5392 years ago
spyse.py preview

spyse.py

GitHubzeropwn/spyse.py

Python API wrapper and command-line client for the tools hosted on spyse.com.

dns-analysisinformation-gatheringosint+2
2706 years ago
xurlfind3r preview

xurlfind3r

GitHubhueristiq/xurlfind3r

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

information-gatheringosintpenetration-testing+2
72310 months ago
AtlasReaper preview

AtlasReaper

GitHubwerdhaihai/atlasreaper

A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.

information-gatheringpenetration-testingreconnaissance+2
2743 years ago
dorky preview

dorky

GitHubcodingo/dorky

A tool to quickly do keyword searches over Gitlab and Github for OSINT & bug bounty recon

information-gatheringosintreconnaissance
2502 years ago
rmm preview

rmm

GitHubalevsk/rmm

Recon MindMap (RMM)

information-gatheringpenetration-testingreconnaissance+1
1843 months ago
rayder preview

rayder

GitHubdevanshbatham/rayder

A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows

penetration-testingreconnaissancescripting-automation+1
3083 years ago
jsfinder preview

jsfinder

GitHubkacakb/jsfinder

Fetches JavaScript files quickly and comprehensively.

crawlerinformation-gatheringreconnaissance+1
1393 years ago
xsubfind3r preview

xsubfind3r

GitHubhueristiq/xsubfind3r

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

dns-subdomain-enumerationinformation-gatheringosint+2
11910 months ago
xcrawl3r preview

xcrawl3r

GitHubhueristiq/xcrawl3r

Recursively spider webpages to discover all URLs by following links, parsing sitemaps, and robots.txt files. Ideal for security reconnaissance and…

crawlerinformation-gatheringpenetration-testing+2
11110 months ago
githubFind3r preview

githubFind3r

GitHubatmoner/githubfind3r

Command-line tool for fast searching of GitHub repositories, users, and commits to gather open-source intelligence and code-related information.

code-analysisinformation-gatheringosint+1
296 years ago
saas_enum preview

saas_enum

GitHubhackinglz/saas_enum

Command-line tool for discovering SaaS platforms a company uses via DNS enumeration

crawlerdns-subdomain-enumerationinformation-gathering+3
421 year ago
rapiddns-cli preview

rapiddns-cli

GitHubrapiddns/rapiddns-cli

A powerful command-line interface for interacting with the [RapidDNS API](https://rapiddns.io/help/api). This tool allows you to perform DNS…

dns-analysisdns-subdomain-enumerationinformation-gathering+3
417 months ago
wp_CVE-2020-35489_checker preview

wp_CVE-2020-35489_checker

GitHubreneoliveirajr/wp_cve-2020-35489_checker

WordPress Sites Vulnerability Checker for CVE-2020-35489 - "Educational Use Only"

educationexploitationinformation-gathering+3
132 years ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
37 months ago
WP2Shell-Scanner preview

WP2Shell-Scanner

GitHubsec-dan/wp2shell-scanner

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

information-gatheringpenetration-testingreconnaissance+3
1 month ago
CVE-2022-24716 preview

CVE-2022-24716

GitHub0x0jackal/cve-2022-24716

Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10

exploitationinformation-gatheringpenetration-testing+3
33 years ago
saas_enum preview

saas_enum

GitLabhackinglz/saas_enum

Command-line tool for discovering SaaS platforms a company uses via DNS enumeration

dns-subdomain-enumerationinformation-gatheringosint+1
1 year ago
Previous123Next