Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
262 results
Sudomy preview

Sudomy

GitHubscreetsec/sudomy

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

dns-analysisinformation-gatheringosint+5
2.4k
2 years ago
BigBountyRecon preview

BigBountyRecon

GitHubviralmaniar/bigbountyrecon

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial…

dns-subdomain-enumerationeducationinformation-gathering+6
1.6k5 years ago
AttackSurfaceMapper preview

AttackSurfaceMapper

GitHubsuperhedgy/attacksurfacemapper

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

information-gatheringosintreconnaissance+1
1.4k2 years ago
ksubdomain preview

ksubdomain

GitHubboy-hack/ksubdomain

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

dns-analysisinformation-gatheringpenetration-testing+2
1.2k4 months ago
infoooze preview

infoooze

GitHubdevxprite/infoooze

A OSINT tool which helps you to quickly find information effectively. All you need is to input and it will take take care of rest.

dns-analysisemail-harvestinginformation-gathering+5
1.1k2 years ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
chiasmodon preview

chiasmodon

GitHubchiasmod0n/chiasmodon

Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves…

dns-subdomain-enumerationemail-harvestinginformation-gathering+5
7001 year ago
ars0n-framework preview

ars0n-framework

GitHubr-s0n/ars0n-framework

Modular bug bounty hunting framework automating reconnaissance, subdomain enumeration, and vulnerability scanning with an educational focus to help…

educationlearning-paths-coursespenetration-testing-frameworks+3
6741 year ago
dnstake preview

dnstake

GitHubpwnesia/dnstake

Fast DNS takeover scanner that checks for missing hosted zones by querying nameservers and fingerprinting providers to identify vulnerable subdomains.

dns-analysisinformation-gatheringsubdomain-enumeration+1
8564 years ago
RTA preview

RTA

GitHubflipkart-incubator/rta

Red team Arsenal - An intelligent scanner to detect security vulnerabilities in company's layer 7 assets.

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+6
4153 years ago
003Recon preview

003Recon

GitHub003random/003recon

Some tools to automate recon - 003random

information-gatheringreconnaissancesubdomain-enumeration+2
2968 years ago
ReconNote preview

ReconNote

GitHub0xdekster/reconnote

Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals &…

information-gatheringpenetration-testingreconnaissance+3
4115 years ago
Monitorizer preview

Monitorizer

GitHubbitthebyte/monitorizer

Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
2872 years ago
chomp-scan preview

chomp-scan

GitHubsolomonsklash/chomp-scan

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

dns-analysisinformation-gatheringpenetration-testing+6
3946 years ago
second-order preview

second-order

GitHubmhmdiaa/second-order

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

crawlerreconnaissancesubdomain-enumeration+2
4081 year ago
wayBackLister preview

wayBackLister

GitHubanmolksachan/waybacklister

A New Approach to Directory Bruteforce with WaybackLister v1.0

information-gatheringmisconfigurationosint+3
2330 years ago
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1495 months ago
Reconky-Automated_Bash_Script preview

Reconky-Automated_Bash_Script

GitHubshivamrai2003/reconky-automated_bash_script

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

information-gatheringosintpenetration-testing+5
2043 years ago
Previous123…15Next