Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
125 results
3klCon preview
Archived

3klCon

GitHubeslam3kl/3klcon

Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.

information-gatheringpenetration-testingport-scanning+3
689
2 years ago
infoooze preview

infoooze

GitHubdevxprite/infoooze

A OSINT tool which helps you to quickly find information effectively. All you need is to input and it will take take care of rest.

dns-analysisemail-harvestinginformation-gathering+5
1.1k2 years ago
rapidscan preview

rapidscan

GitHubskavngr/rapidscan

:new: The Multi-Tool Web Vulnerability Scanner.

dns-analysisinformation-gatheringpenetration-testing+5
2.1k3 years ago
AttackSurfaceMapper preview

AttackSurfaceMapper

GitHubsuperhedgy/attacksurfacemapper

Automated reconnaissance tool that expands attack surface via OSINT and active techniques, enumerating subdomains, mapping network blocks, and…

information-gatheringosintreconnaissance+1
1.4k2 years ago
kostebek preview

kostebek

GitHubesecuritylab/kostebek

Automated reconnaissance tool that discovers organization domains by querying trademark databases via Google, Bing, Yahoo, and trademark registries.

information-gatheringosintreconnaissance+1
906 years ago
recon-ninja preview

recon-ninja

GitHubtess-ss/recon-ninja

Subdomain reconnaissance platform with HTTPX live-host probing, MongoDB-backed storage, searchable UI, and Nuclei vulnerability scanning with Discord…

information-gatheringpenetration-testingreconnaissance+3
882 years ago
HOCig1_2 preview

HOCig1_2

GitHubhackersonlineclub/hocig1_2

HOCig- Automatic HOC Information Gathering Tool V 1.2

dns-analysisemail-securityinformation-gathering+5
115 years ago
ct-exposer preview

ct-exposer

GitHubchris408/ct-exposer

An OSINT tool that discovers sub-domains by searching Certificate Transparency logs

dns-analysisinformation-gatheringosint+3
4874 years ago
dnsprobe preview
Archived

dnsprobe

GitHubprojectdiscovery/dnsprobe

DNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

dns-analysisinformation-gatheringnetwork-mapping+3
2855 years ago
OSINT-Framework preview

OSINT-Framework

GitHublockfale/osint-framework

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

curated-resourcesdns-subdomain-enumerationeducation+8
12k4 months ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

fingerprint-spoofinginformation-gatheringosint+6
88618 days ago
Striker preview

Striker

GitHubs0md3v/striker

Multi-phase recon and vulnerability scanner that discovers subdomains, scans ports, detects CMS/technologies, and checks for misconfigured headers…

information-gatheringport-scanningreconnaissance+3
2.3k7 years ago
wayBackLister preview

wayBackLister

GitHubanmolksachan/waybacklister

Fetches archived URLs from the Wayback Machine, extracts unique paths and subdomains, and checks for exposed directory listings for web recon and bug…

information-gatheringmisconfigurationosint+3
2330 years ago
web-scanner preview

web-scanner

GitHubcapture0x/web-scanner

Python-based web domain scanner integrating Sublist3r, Dirble, Nmap, and WhatWeb for subdomain discovery, directory enumeration, network scanning,…

information-gatheringnetwork-mappingreconnaissance+3
233 months ago
domain-to-webapp preview

domain-to-webapp

GitHubcyberblackhole/domain-to-webapp

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

information-gatheringpenetration-testingreconnaissance+2
57 years ago
dns-zone-transfer-test preview

dns-zone-transfer-test

GitHubrodney-o-c-melby/dns-zone-transfer-test

Automates DNS zone transfer testing by discovering nameservers and checking for misconfigurations, printing exposed subdomains when vulnerable.

dns-analysisinformation-gatheringnetwork-security+3
31 year ago
BugBountyScanner preview

BugBountyScanner

GitHubchvancooten/bugbountyscanner

A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.

crawlerinformation-gatheringpenetration-testing+5
9229 months ago
spyse.py preview

spyse.py

GitHubzeropwn/spyse.py

Python API wrapper and command-line client for the tools hosted on spyse.com.

dns-analysisinformation-gatheringosint+2
2706 years ago
Previous1234567Next