Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.2k
2 days ago
claude-bug-bounty preview

claude-bug-bounty

GitHubshuvonsec/claude-bug-bounty

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

ai-securitycloud-securityexploitation+8
4.3k10 days ago
tactical-exploitation preview

tactical-exploitation

GitHub0xdea/tactical-exploitation

Modern tactical exploitation toolkit.

exploitationinformation-gatheringosint+8
86618 days ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k20 days ago
sif preview

sif

GitHubvmfunc/sif

the blazing-fast pentesting suite.

crawlerdns-analysisexploitation+7
61229 days ago
Subhunter preview

Subhunter

GitHubumutcamliyurt/subhunter

Fast subdomain takeover scanner that checks DNS CNAME records against known fingerprints to detect vulnerable subdomains. Built in Go with…

penetration-testingsubdomain-enumerationvulnerability-scanners+1
883 months ago
emploleaks preview

emploleaks

GitHubinfobyte/emploleaks

An OSINT tool that helps detect members of a company with leaked credentials

data-exfiltrationemail-harvestinginformation-gathering+8
7873 months ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182
command-and-controlexploitationpayload-generation+7
4 months ago
subjack preview

subjack

GitHubhaccer/subjack

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

dns-analysispenetration-testingsubdomain-enumeration+2
2.1k5 months ago
ore_react2shell_scanner preview

ore_react2shell_scanner

GitHubrapticore/ore_react2shell_scanner

CVE-2025-55182 (React2Shell) Scanner

exploitationpenetration-testingreconnaissance+4
25 months ago
RedTeam_toolkit preview

RedTeam_toolkit

GitHubsignorrayan/redteam_toolkit

Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.

exploitationinformation-gatheringpassword-attacks+5
5726 months ago
react2shell preview

react2shell

GitHubtermireum/react2shell

React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE)…

exploitationpenetration-testingreconnaissance+3
7 months ago
Torito-R2S preview

Torito-R2S

GitHubtoritoio/torito-r2s

Torito React2Shell Scanner & Exploit Tool (CVE-2025-55182 / 66478)

command-and-controlexploitationpenetration-testing+4
48 months ago
AISA-Scanner preview

AISA-Scanner

GitHubgmh5225/aisa-scanner

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

ai-securityexploitationpenetration-testing+6
11 year ago
Ladon preview

Ladon

GitHubk8gege/ladon

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32…

exploitationinformation-gatheringlateral-movement+9
5.3k1 year ago
easy_security preview

easy_security

GitHubmoon1705/easy_security

Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.

exploitationinformation-gatheringnetwork-security+5
2 years ago
-CVE-2023-30845 preview

-CVE-2023-30845

GitHubhimori123/-cve-2023-30845

Explore CVE 2023-30845 automatically across multiple subdomains

exploitationreconnaissancesubdomain-enumeration+2
162 years ago
PY-Log4j-RCE-Scanner preview

PY-Log4j-RCE-Scanner

GitHubmrharshvardhan/py-log4j-rce-scanner

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

dns-analysisexploitationreconnaissance+3
43 years ago
Previous12Next