Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

api-security-testingcloud-securityconfiguration-auditing+8
30.6k12h 36m ago
claude-bug-bounty preview

claude-bug-bounty

GitHubshuvonsec/claude-bug-bounty

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

ai-securitycloud-securityexploitation+8
4.3k10 days ago
lazyrecon preview

lazyrecon

GitHubnahamsec/lazyrecon

This script is intended to automate your reconnaissance process in an organized fashion

dns-analysisinformation-gatheringpenetration-testing+3
2.0k6 years ago
AttackSurfaceMapper preview

AttackSurfaceMapper

GitHubsuperhedgy/attacksurfacemapper

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

information-gatheringosintreconnaissance+1
1.4k2 years ago
resolvers preview

resolvers

GitHubtrickest/resolvers

Curated, continuously validated list of reliable DNS resolvers for DNS enumeration, reconnaissance, and bug bounty workflows.

curated-resourcesdns-analysisdns-subdomain-enumeration+6
1.0k5 days ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5535 months ago
frogy2.0 preview

frogy2.0

GitHubiamthefrogy/frogy2.0

Orbis is an full spectrum automated external attack surface intelligent toolkit.

cloud-securitydns-analysisemail-security+9
4007 days ago
celerystalk preview
Archived

celerystalk

GitHubsethsec/celerystalk

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

crawlerdns-subdomain-enumerationinformation-gathering+8
4005 years ago
sub.sh preview

sub.sh

GitHubcihanmehmet/sub.sh

Multiprocessing(Parallel)Subdomain Detect Script

dns-subdomain-enumerationinformation-gatheringosint+2
3272 years ago
megplus preview
Archived

megplus

GitHubedoverflow/megplus

Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]

crawlerinformation-gatheringmisconfiguration+5
3037 years ago
Rock-ON preview

Rock-ON

GitHubsilverpoision/rock-on

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

crawlerdns-subdomain-enumerationinformation-gathering+5
2906 years ago
Monitorizer preview

Monitorizer

GitHubbitthebyte/monitorizer

Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
2872 years ago
dnsprobe preview
Archived

dnsprobe

GitHubprojectdiscovery/dnsprobe

DNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

dns-analysisinformation-gatheringnetwork-mapping+3
2855 years ago
ghostbuster preview

ghostbuster

GitHubassetnote/ghostbuster

Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.

cloud-securitydns-analysisreconnaissance+2
2781 year ago
instarecon preview

instarecon

GitHubvergl4s/instarecon

Automated digital reconnaissance

dns-analysisinformation-gatheringosint+2
2043 years ago
InfoHound preview

InfoHound

GitHubfundacio-i2cat/infohound

InfoHound is an OSINT to extract a large amount of data given a web domain name.

dns-analysiseducationemail-harvesting+8
1632 years ago
scriptkiddi3 preview

scriptkiddi3

GitHubthecyberneh/scriptkiddi3

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

penetration-testingreconnaissancesubdomain-enumeration+1
1522 years ago
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1495 months ago
Previous12Next