Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
116 results
Shockwave-OSS preview

Shockwave-OSS

GitHubgal-nagli/shockwave-oss

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

curated-resourceseducationfuzzing+9
750
2 years ago
HostileSubBruteforcer preview

HostileSubBruteforcer

GitHubnahamsec/hostilesubbruteforcer

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

cloud-securitydns-subdomain-enumerationinformation-gathering+3
4829 years ago
Dome preview

Dome

GitHubv4d1/dome

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

dns-analysisosintpenetration-testing+3
5452 years ago
Reconator preview

Reconator

GitHubgokulapap/reconator

Automated Recon for Pentesting & Bug Bounty

dns-subdomain-enumerationfuzzinginformation-gathering+6
4412 days ago
vortex preview

vortex

GitHubklezvirus/vortex

VPN Overall Reconnaissance, Testing, Enumeration and eXploitation Toolkit

information-gatheringosintpassword-attacks+7
4504 years ago
recox preview

recox

GitHubsamhaxr/recox

Master script for web reconnaissance

information-gatheringpenetration-testingreconnaissance+3
3363 years ago
Bug-Bounty-Wordlists preview

Bug-Bounty-Wordlists

GitHubya551n3/bug-bounty-wordlists

Curated collection of wordlists for bug bounty hunting, covering directories, subdomains, parameters, usernames, passwords, and web fuzzing payloads.

curated-resourcesfuzzinginformation-gathering+3
6358 months ago
jsubfinder preview

jsubfinder

GitHubthreatunknown/jsubfinder

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

information-gatheringosintreconnaissance+3
2831 year ago
second-order preview

second-order

GitHubmhmdiaa/second-order

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

crawlerreconnaissancesubdomain-enumeration+2
4081 year ago
wayBackLister preview

wayBackLister

GitHubanmolksachan/waybacklister

A New Approach to Directory Bruteforce with WaybackLister v1.0

information-gatheringmisconfigurationosint+3
2331 year ago
censys-enumeration preview

censys-enumeration

GitHub0xbharath/censys-enumeration

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys

email-harvestinginformation-gatheringosint+2
1563 years ago
Ashok preview

Ashok

GitHubpowerexploit/ashok

Ashok is a OSINT Recon Tool , a.k.a 😍 Swiss Army knife .

dns-analysisinformation-gatheringosint+4
4454 years ago
kanha preview

kanha

GitHubpwnwriter/kanha

🦚 A web-app pentesting suite written in rust .

dns-subdomain-enumerationfuzzinginformation-gathering+5
3241 year ago
ID-entify preview

ID-entify

GitHubbillyv4/id-entify

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

dns-analysisemail-harvestinginformation-gathering+4
1166 years ago
domains-from-csp preview

domains-from-csp

GitHub0xbharath/domains-from-csp

A script to extract domain names from Content Security Policy(CSP) headers

dns-analysisinformation-gatheringnetwork-mapping+5
1137 years ago
vhosts-sieve preview

vhosts-sieve

GitHubdariusztytko/vhosts-sieve

Searching for virtual hosts among non-resolvable domains

information-gatheringpenetration-testingreconnaissance+2
886 years ago
PortWitness preview

PortWitness

GitHubviperbluff/portwitness

Tool for checking Whether a domain or its multiple sub-domains are up and running.

information-gatheringport-scanningreconnaissance+1
717 years ago
subgen preview

subgen

GitHubpry0cc/subgen

A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
856 years ago
Previous1234567Next