Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
CVE-2025-53770-Scanner preview

CVE-2025-53770-Scanner

GitHubsec-dan/cve-2025-53770-scanner

A Python-based reconnaissance scanner for safely identifying potential exposure to SharePoint vulnerability CVE-2025-53770.

information-gatheringpenetration-testingreconnaissance+3
3
1 year ago
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k1 month ago
Recon preview

Recon

GitHubdirsoooo/recon

Recon is a script to perform a full recon on a target with the main tools to search for vulnerabilities. Created based on @ofjaaah and @Jhaddix…

dns-analysisinformation-gatheringosint+6
2224 years ago
project-black preview

project-black

GitHubc0rv4x/project-black

Pentest/BugBounty progress control with scanning modules

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
2796 years ago
PCWT preview

PCWT

GitHubascr0b/pcwt

Web-based project management interface for penetration testing and bug bounty workflows, automating port scanning with Nmap/Masscan and subdomain…

information-gatheringpenetration-testingpenetration-testing-frameworks+5
465 years ago
cloud-buster preview
Archived

cloud-buster

GitHubsagehack/cloud-buster

A Cloudflare resolver that works

dns-analysisinformation-gatheringmisconfiguration+5
1457 years ago
Vxscan preview

Vxscan

GitHubal0ne/vxscan

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

crawlerinformation-gatheringosint+7
1.8k6 years ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
8901 month ago
getaltname preview

getaltname

GitHubfranccesco/getaltname

Extract subdomains from SSL certificates in HTTPS sites.

dns-subdomain-enumerationinformation-gatheringpenetration-testing+2
3902 months ago
subscraper preview

subscraper

GitHubm8sec/subscraper

Subdomain and target enumeration tool built for offensive security testing

dns-analysisinformation-gatheringosint+3
9752 years ago
Searpy preview

Searpy

GitHubj3ers3/searpy

🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找

dns-subdomain-enumerationinformation-gatheringosint+3
2143 years ago
Ladon preview

Ladon

GitHubk8gege/ladon

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32…

exploitationinformation-gatheringlateral-movement+9
5.3k1 year ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.1k13 days ago
pentx-vapt-skill preview

pentx-vapt-skill

GitHubyashas-13/pentx-vapt-skill

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC

exploitationinformation-gatheringpenetration-testing+6
219 days ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.3k13 days ago
vulnx preview

vulnx

GitHubanouarbensaad/vulnx

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform…

crawlerdns-analysisexploit-frameworks+5
2.1k4 years ago
sif preview

sif

GitHubvmfunc/sif

the blazing-fast pentesting suite.

crawlerdns-analysisexploitation+7
58823 days ago
gOSINT preview

gOSINT

GitHubnhoya/gosint

OSINT Swiss Army Knife

crawlerdns-subdomain-enumerationemail-harvesting+6
6747 years ago
Previous12Next