Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

information-gatheringnetwork-securitypassword-attacks+7
5.5k
7h 43m ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

api-security-testingcloud-securityconfiguration-auditing+8
30.6k22h 57m ago
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.2k2 days ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
88614 days ago
NetLogic preview

NetLogic

GitHubdmitryflynn/netlogic

NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection

ai-securitycloud-securitydns-analysis+7
11 month ago
KingOfBugBountyTips preview

KingOfBugBountyTips

GitHubkingofbugbounty/kingofbugbountytips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

curated-resourceseducationosint+5
5.5k1 month ago
Subhunter preview

Subhunter

GitHubumutcamliyurt/subhunter

Fast subdomain takeover scanner that checks DNS CNAME records against known fingerprints to detect vulnerable subdomains. Built in Go with…

penetration-testingsubdomain-enumerationvulnerability-scanners+1
883 months ago
Garud preview

Garud

GitHubr0x4r/garud

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

penetration-testingreconnaissancesubdomain-enumeration+2
8113 months ago
Raccoon preview

Raccoon

GitHubevyatarmeged/raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning

dns-analysisfuzzinginformation-gathering+6
4.0k4 months ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182
command-and-controlexploitationpayload-generation+7
4 months ago
subjack preview

subjack

GitHubhaccer/subjack

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

dns-analysispenetration-testingsubdomain-enumeration+2
2.1k5 months ago
ore_react2shell_scanner preview

ore_react2shell_scanner

GitHubrapticore/ore_react2shell_scanner

CVE-2025-55182 (React2Shell) Scanner

exploitationpenetration-testingreconnaissance+4
25 months ago
react2shell preview

react2shell

GitHubtermireum/react2shell

React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE)…

exploitationpenetration-testingreconnaissance+3
7 months ago
react2shell-scanner-CVE-2025-55182 preview

react2shell-scanner-CVE-2025-55182

GitHubsecurity-phoenix-demo/react2shell-scanner-cve-2025-55182

React2shell-web-scanner

educationexploitationioc-management+6
28 months ago
CVE-2025-55182-Simple-Scanner-main preview

CVE-2025-55182-Simple-Scanner-main

GitHubjan0x190/cve-2025-55182-simple-scanner-main
educationexploitationpenetration-testing+4
18 months ago
bug-bounty-reports-desai-vinayak preview

bug-bounty-reports-desai-vinayak

GitHubdesaivinayak449/bug-bounty-reports-desai-vinayak

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

cloud-securitycurated-resourcesdns-analysis+6
9 months ago
CVE-2025-53770-Scanner preview

CVE-2025-53770-Scanner

GitHubsec-dan/cve-2025-53770-scanner

A Python-based reconnaissance scanner for safely identifying potential exposure to SharePoint vulnerability CVE-2025-53770.

information-gatheringpenetration-testingreconnaissance+3
31 year ago
AISA-Scanner preview

AISA-Scanner

GitHubgmh5225/aisa-scanner

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

ai-securityexploitationpenetration-testing+6
11 year ago
Previous123Next