Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
warf preview

warf

GitHubiamnihal/warf

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

information-gatheringosintpenetration-testing+3
194
4 years ago
maigret preview

maigret

GitHubsoxoj/maigret

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

crawlerdns-subdomain-enumerationemail-harvesting+7
36.9k12h 13m ago
OSINT-Framework preview

OSINT-Framework

GitHublockfale/osint-framework

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

curated-resourcesdns-subdomain-enumerationeducation+7
12.0k4 months ago
bbot preview

bbot

GitHubblacklanternsecurity/bbot

The recursive internet scanner for hackers. 🧡

crawlerdns-analysisemail-harvesting+8
10.5k1 month ago
KingOfBugBountyTips preview

KingOfBugBountyTips

GitHubkingofbugbounty/kingofbugbountytips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

curated-resourceseducationosint+5
5.5k1 month ago
claude-bug-bounty preview

claude-bug-bounty

GitHubshuvonsec/claude-bug-bounty

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

ai-securitycloud-securityexploitation+8
4.3k10 days ago
Findomain preview

Findomain

GitHubfindomain/findomain

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

dns-subdomain-enumerationinformation-gatheringosint+2
3.8k29 days ago
datasploit preview

datasploit

GitHubdatasploit/datasploit

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

dns-subdomain-enumerationemail-harvestinginformation-gathering+6
3.3k9 months ago
waymore preview

waymore

GitHubxnl-h4ck3r/waymore

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!

crawlerinformation-gatheringosint+3
2.7k2 months ago
xray preview
Archived

xray

GitHubevilsocket/xray

XRay is a tool for recon, mapping and OSINT gathering from public networks.

dns-analysisdns-subdomain-enumerationinformation-gathering+5
2.3k2 years ago
ReconDog preview

ReconDog

GitHubs0md3v/recondog

Reconnaissance Swiss Army Knife

dns-analysisinformation-gatheringosint+3
2.1k7 years ago
SubOver preview

SubOver

GitHubice3man543/subover

A Powerful Subdomain Takeover Tool

penetration-testingsubdomain-enumerationvulnerability-analysis+1
9697 years ago
censys-subdomain-finder preview

censys-subdomain-finder

GitHubchristophetd/censys-subdomain-finder

⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

dns-subdomain-enumerationinformation-gatheringosint+2
8431 year ago
emploleaks preview

emploleaks

GitHubinfobyte/emploleaks

An OSINT tool that helps detect members of a company with leaked credentials

data-exfiltrationemail-harvestinginformation-gathering+8
7873 months ago
OTE preview
Archived

OTE

GitHub3nock/ote

OSINT Template Engine

information-gatheringosintreconnaissance+1
57914 days ago
Belati preview
Archived

Belati

GitHubaancw/belati

The Traditional Swiss Army Knife for OSINT

crawlerdns-analysiseducation+5
5665 years ago
Dome preview

Dome

GitHubv4d1/dome

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

dns-analysisosintpenetration-testing+3
5452 years ago
ReconNote preview

ReconNote

GitHub0xdekster/reconnote

Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals &…

information-gatheringpenetration-testingreconnaissance+3
4115 years ago
Previous12Next