Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
CVE-2025-12139-WordPress-Integrate-Google-Drive-Exploit preview

CVE-2025-12139-WordPress-Integrate-Google-Drive-Exploit

GitHubgalaxy-sc/cve-2025-12139-wordpress-integrate-google-drive-exploit

Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

exploitationinformation-gatheringpenetration-testing+3
8 months ago
subdosec preview

subdosec

GitHubxcapri/subdosec

Fast, accurate subdomain takeover scanner with zero false positives. Detects vulnerable subdomains, collects metadata (IP, CNAME, title, status…

information-gatheringreconnaissancesubdomain-enumeration+2
633 months ago
s3dns preview

s3dns

GitHubolizimmermann/s3dns

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

cloud-securitydns-analysisinformation-gathering+5
1285 days ago
sub404 preview
Archived

sub404

GitHubr3curs1v3-pr0xy/sub404

A python tool to check subdomain takeover vulnerability

dns-analysispenetration-testingreconnaissance+3
3523 years ago
domain-protect preview

domain-protect

GitHubovotech/domain-protect

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

cloud-securitymisconfigurationreconnaissance+1
33 years ago
CVE-2026-39912 preview

CVE-2026-39912

GitHubchocapikk/cve-2026-39912

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

authenticationexploitationinformation-gathering+4
24 months ago
CVE-2026-27886-check preview

CVE-2026-27886-check

GitHubbishopfox/cve-2026-27886-check

Detect whether a Strapi instance is vulnerable to CVE-2026-27886 (unauthenticated boolean-oracle exfiltration of administrator secrets).

exploitationinformation-gatheringpenetration-testing+3
13 months ago
CVE-2020-35847_CVE-2020-35848 preview

CVE-2020-35847_CVE-2020-35848

GitHubw33vils/cve-2020-35847_cve-2020-35848

CVE-2020-35847, CVE-2020-35848 : Account Takeover

exploitationinformation-gatheringpassword-attacks+3
3 years ago
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k12 days ago
OneForAll preview

OneForAll

GitHubshmilylty/oneforall

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

dns-analysisinformation-gatheringosint+3
10.0k3 months ago
WebHackersWeapons preview

WebHackersWeapons

GitHubhahwul/webhackersweapons

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

curated-resourceseducationexploit-frameworks+7
5.0k5 months ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k4 days ago
pretender preview

pretender

GitHubredteampentesting/pretender

Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.

authenticationdns-analysisinformation-gathering+4
1.3k1 month ago
Rock-ON preview

Rock-ON

GitHubsilverpoision/rock-on

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

crawlerdns-subdomain-enumerationinformation-gathering+5
2906 years ago
Reconky-Automated_Bash_Script preview

Reconky-Automated_Bash_Script

GitHubshivamrai2003/reconky-automated_bash_script

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

information-gatheringosintpenetration-testing+5
2043 years ago
Horn3t preview

Horn3t

GitHubjanniskirschner/horn3t

Powerful Visual Subdomain Enumeration at the Click of a Mouse

information-gatheringpenetration-testingreconnaissance+2
1387 years ago
badsuccessor preview

badsuccessor

GitHubcybrly/badsuccessor

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

adversarial-attackexploitationinformation-gathering+7
1221 year ago
CVE-2026-27886-PoC-Account-Takeover preview

CVE-2026-27886-PoC-Account-Takeover

GitHubthesw0rd/cve-2026-27886-poc-account-takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

exploitationinformation-gatheringpassword-attacks+4
22 months ago
Previous1234Next