Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
851 results
tweets_analyzer preview

tweets_analyzer

GitHubx0rz/tweets_analyzer

OSINT tool that scrapes Twitter profile metadata to analyze activity patterns, timezone, language, geolocation, hashtags, and social connections for…

information-gatheringosintreconnaissance+1
3.0k
6 years ago
007-TheBond preview

007-TheBond

GitHubdeadshot0x7/007-thebond

This Script will help you to gather information about your victim or friend.

dns-subdomain-enumerationeducationemail-harvesting+5
1.5k1 month ago
GooFuzz preview

GooFuzz

GitHubm3n0sd0n4ld/goofuzz

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

dns-subdomain-enumerationfuzzinginformation-gathering+3
1.6k8 months ago
PenBox preview

PenBox

GitHubx3omdax/penbox

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

exploitationfuzzinginformation-gathering+8
5359 years ago
jsmon preview

jsmon

GitHubrobre/jsmon

a javascript change monitoring tool for bugbounties

crawlerinformation-gatheringreconnaissance+1
7375 years ago
uDork preview

uDork

GitHubm3n0sd0n4ld/udork

uDork is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories, find…

information-gatheringosintreconnaissance+2
8594 years ago
Dome preview

Dome

GitHubv4d1/dome

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

dns-analysisosintpenetration-testing+3
5452 years ago
recox preview

recox

GitHubsamhaxr/recox

Master script for web reconnaissance

information-gatheringpenetration-testingreconnaissance+3
3363 years ago
cypherhound preview

cypherhound

GitHubfin3ss3g0d/cypherhound

Your template-based BloodHound terminal companion tool

information-gatheringpenetration-testingreconnaissance+1
4557 months ago
ProtOSINT preview

ProtOSINT

GitHubpixelbubble/protosint

ProtOSINT is a Python script that helps you investigate Proton Mail accounts.

email-harvestinginformation-gatheringosint+1
4271 month ago
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1495 months ago
RDWAtool preview

RDWAtool

GitHubp0dalirius/rdwatool

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application

information-gatheringpassword-attacksreconnaissance+1
1227 months ago
CertCrunchy preview

CertCrunchy

GitHubjoda32/certcrunchy

Just a silly recon tool that uses data from SSL Certificates to find potential host names

dns-subdomain-enumerationinformation-gatheringosint+1
293 months ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
6 days ago
CVE-2024-24919-Sniper preview

CVE-2024-24919-Sniper

GitHubbigb0x/cve-2024-24919-sniper

CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning,…

exploitationinformation-gatheringpenetration-testing+3
32 years ago
dns-zone-audit preview

dns-zone-audit

GitHubsleepthegod/dns-zone-audit

This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

dns-analysisinformation-gatheringmisconfiguration+3
15 months ago
EternalBlue-Vulnerability-Scanner preview

EternalBlue-Vulnerability-Scanner

GitHubmedx267/eternalblue-vulnerability-scanner

This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.

exploitationinformation-gatheringnetwork-security+3
11 year ago
CVE-2024-38063-scanner preview

CVE-2024-38063-scanner

GitHubjip-0-0-0-0-0/cve-2024-38063-scanner

A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service…

exploitationinformation-gatheringpacket-sniffing-analysis+2
11 year ago
Previous123…48Next