Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
140 results
claude-bug-bounty preview

claude-bug-bounty

GitHubawarexone/claude-bug-bounty

AI-powered bug bounty hunting toolkit that works with or without subscription.

ai-securityapi-security-testingcloud-security+7
4.4k
5 days ago
subscraper preview

subscraper

GitHubm8sec/subscraper

Subdomain and target enumeration tool built for offensive security testing

dns-analysisinformation-gatheringosint+3
9732 years ago
pentx-vapt-skill preview

pentx-vapt-skill

GitHubyashas-13/pentx-vapt-skill

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC

exploitationinformation-gatheringpenetration-testing+6
2 days ago
AISA-Scanner preview

AISA-Scanner

GitHubgmh5225/aisa-scanner

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

ai-securityexploitationpenetration-testing+6
11 year ago
dnsx-action preview

dnsx-action

GitHubprojectdiscovery/dnsx-action

Fast and multi-purpose DNS toolkit allow to run multiple DNS queries.

dns-analysisinformation-gatheringnetwork-mapping+3
154 years ago
TakeOver-v1 preview

TakeOver-v1

GitHubsamhaxr/takeover-v1

Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover…

dns-analysissubdomain-enumerationvulnerability-analysis+1
1003 years ago
bug-bounty-domains preview
Archived

bug-bounty-domains

GitHubarpsyndicate/bug-bounty-domains

Domains belonging to the most reputed public bug bounty programs. [NOT FOR NON-MONETARY OR PRIVATE PROGRAMS]

curated-resourcesinformation-gatheringosint+2
2272 years ago
web-check preview

web-check

GitHublissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

dns-analysisemail-harvestinginformation-gathering+10
34.6k1 day ago
theHarvester preview

theHarvester

GitHublaramies/theharvester

E-mails, subdomains and names Harvester - OSINT

dns-analysisdns-subdomain-enumerationemail-harvesting+9
17.2k2h 28m ago
BigBountyRecon preview

BigBountyRecon

GitHubviralmaniar/bigbountyrecon

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial…

dns-subdomain-enumerationeducationinformation-gathering+6
1.6k5 years ago
claude-bug-bounty preview

claude-bug-bounty

GitHubshuvonsec/claude-bug-bounty

AI-powered bug bounty hunting toolkit that works with or without subscription.

ai-securitycloud-securityexploitation+8
4.5k3 days ago
subjack preview

subjack

GitHubhaccer/subjack

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

dns-analysispenetration-testingsubdomain-enumeration+2
2.1k5 months ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.0k2 months ago
warf preview

warf

GitHubiamnihal/warf

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

information-gatheringosintpenetration-testing+3
1944 years ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k4 days ago
KingOfBugBountyTips preview

KingOfBugBountyTips

GitHubkingofbugbounty/kingofbugbountytips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

curated-resourceseducationosint+5
5.5k1 month ago
ars0n-framework preview

ars0n-framework

GitHubr-s0n/ars0n-framework

Modular bug bounty hunting framework automating reconnaissance, subdomain enumeration, and vulnerability scanning with an educational focus to help…

educationlearning-paths-coursespenetration-testing-frameworks+3
6741 year ago
assetfinder preview

assetfinder

GitHubtomnomnom/assetfinder

Find domains and subdomains related to a given domain

dns-subdomain-enumerationinformation-gatheringosint+2
3.7k6 years ago
Previous12…8Next