Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
naabu preview

naabu

GitHubprojectdiscovery/naabu

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

information-gatheringnetwork-mappingpenetration-testing+3
6.2k
1 day ago
SteppingStones preview

SteppingStones

GitHubnccgroup/steppingstones

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

command-and-controlinformation-gatheringpenetration-testing+3
2434 days ago
aardwolf preview

aardwolf

GitHubskelsec/aardwolf

Asynchronous RDP client for Python (headless)

authenticationinformation-gatheringlateral-movement+5
2389 days ago
wp2shell-vulnerability-scanner preview

wp2shell-vulnerability-scanner

GitHubadrees-basheer/wp2shell-vulnerability-scanner

Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

information-gatheringreconnaissancescripting-automation+3
1 month ago
dscanner preview

dscanner

GitHubalan-baigorria/dscanner

Automated web reconnaissance tool consolidating dig, nmap, httpx, curl, and whois into a single scan for IP resolution, port discovery, technology…

dns-analysisinformation-gatheringnetwork-mapping+6
11 month ago
thrunt-god preview

thrunt-god

GitHubbackbay-labs/thrunt-god

Threat hunting command system for agentic IDEs

incident-responseinformation-gatheringintrusion-detection+5
361 month ago
URS preview

URS

GitHubjosephlai241/urs

Universal Reddit Scraper - A comprehensive Reddit scraping/archival command-line tool.

crawlerinformation-gatheringosint+1
1.0k1 month ago
caplets preview

caplets

GitHubbettercap/caplets

Scriptable MITM attack modules and automation caplets for the Bettercap framework, enabling network reconnaissance, traffic manipulation, and Wi-Fi…

exploitationinformation-gatheringnetwork-security+4
5231 month ago
Cortex preview

Cortex

GitHubthehive-project/cortex

Automated observable analysis engine for threat intelligence, digital forensics, and incident response, integrating with diverse analyzers via a…

digital-forensicsincident-responseinformation-gathering+5
1.6k1 month ago
cygor preview

cygor

GitHubtjnull/cygor

An modular asset discovery framework written in python to automate the repeating manual work

database-securitydns-analysisinformation-gathering+7
882 months ago
AutoDirbuster preview

AutoDirbuster

GitHubnetspi/autodirbuster

Automatically run and save ffuf scans for multiple IPs

information-gatheringreconnaissancescripting-automation+2
822 months ago
DiffCatcher preview

DiffCatcher

GitHubteycir/diffcatcher

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

code-analysisdevsecopsinformation-gathering+7
44 months ago
GETROBARB preview

GETROBARB

GitHubhackingteamoficial/getrobarb

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

crawlerdns-analysisinformation-gathering+7
94 months ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

CLI tool for automating HTTP request routing through Burp Suite proxy to load reconnaissance URLs and streamline web application security testing…

penetration-testingreconnaissancescripting-automation+2
105 months ago
SubMon preview

SubMon

GitHubliuyc26/submon

Automated subdomain monitoring tool with scheduled scanning, Discord alerts, and a web dashboard. Uses subfinder, dnsx, and httpx to detect new and…

dns-analysisinformation-gatheringreconnaissance+3
15 months ago
CVE-2025-15467 preview

CVE-2025-15467

GitHubmr-r3b00t/cve-2025-15467

PowerShell-based discovery tool for CVE-2025-15467, enabling automated vulnerability detection and exploitation assessment in target environments.

exploitationinformation-gatheringpenetration-testing+3
16 months ago
smb preview

smb

GitHubhackingyseguridad/smb

Shell script collection for SMB protocol auditing, vulnerability detection (EternalBlue, SMBGhost), null session enumeration, credential brute-force,…

exploitationinformation-gatheringnetwork-security+5
7 months ago
gaia preview

gaia

GitHuboksuzkayra/gaia

Attack surface discovery and AI-assisted triage for security researchers. Endpoint & parameter mapping with actionable testing hints.

ai-securitycrawlerinformation-gathering+7
467 months ago
Previous1234Next