Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
can-i-take-over-xyz preview

can-i-take-over-xyz

GitHubedoverflow/can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

curated-resourceseducationsubdomain-enumeration+1
5.8k
1 year ago
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k21 days ago
resolvers preview

resolvers

GitHubtrickest/resolvers

Curated, continuously validated list of reliable DNS resolvers for DNS enumeration, reconnaissance, and bug bounty workflows.

curated-resourcesdns-analysisdns-subdomain-enumeration+6
1.0k5 days ago
One-Liner-Collections preview

One-Liner-Collections

GitHubcybertix-pvt-ltd/one-liner-collections

This Repositories contains list of One Liners with Descriptions and Installation requirements

curated-resourcesinformation-gatheringpenetration-testing+5
5091 year ago
NtHiM preview

NtHiM

GitHubthebinitghimire/nthim

Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection!

dns-analysisdns-subdomain-enumerationmisconfiguration+3
3874 years ago
Spartan preview

Spartan

GitHubmad-robot/spartan

Automated reconnaissance framework integrating subdomain enumeration, live host probing, port scanning, CMS detection, and directory brute-forcing…

information-gatheringpenetration-testingport-scanning+3
1935 years ago
Reconky-Automated_Bash_Script preview

Reconky-Automated_Bash_Script

GitHubshivamrai2003/reconky-automated_bash_script

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

information-gatheringosintpenetration-testing+5
2043 years ago
getsubdomain preview

getsubdomain

GitHubabaykan/getsubdomain

Get subdomain list and check whether they are active or not by each response code. Using API by c99.nl

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
84 years ago
Sububy preview

Sububy

GitHuba3h1nt/sububy

Modular subdomain enumeration suite with certificate transparency, DNS brute-force, and API-based discovery. Includes post-enumeration modules for…

dns-subdomain-enumerationinformation-gatheringosint+2
71 year ago
ReconHound preview

ReconHound

GitLabs_r_e_e_r_a_j/reconhound

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

fuzzinginformation-gatheringpenetration-testing+3
14 months ago
dnsprobe preview
Archived

dnsprobe

GitHubprojectdiscovery/dnsprobe

DNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

dns-analysisinformation-gatheringnetwork-mapping+3
2855 years ago
3klCon preview
Archived

3klCon

GitHubeslam3kl/3klcon

Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.

information-gatheringpenetration-testingport-scanning+3
6892 years ago
bug-bounty-domains preview
Archived

bug-bounty-domains

GitHubarpsyndicate/bug-bounty-domains

Domains belonging to the most reputed public bug bounty programs. [NOT FOR NON-MONETARY OR PRIVATE PROGRAMS]

curated-resourcesinformation-gatheringosint+2
2271 year ago
awesome-attack-surface-management preview

awesome-attack-surface-management

GitHubescape-technologies/awesome-attack-surface-management

A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).

cloud-securitycurated-resourcesdns-analysis+7
397 months ago
web-check preview

web-check

GitHublissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

dns-analysisinformation-gatheringnetwork-mapping+8
34.6k9 days ago
MicroBurst preview

MicroBurst

GitHubnetspi/microburst

A collection of scripts for assessing Microsoft Azure security

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
2.4k1 month ago
gasmask preview

gasmask

GitHubtwelvesec/gasmask

Information gathering tool - OSINT

dns-analysisemail-harvestinginformation-gathering+4
1.5k5 years ago
HostileSubBruteforcer preview

HostileSubBruteforcer

GitHubnahamsec/hostilesubbruteforcer
cloud-securitydns-subdomain-enumerationinformation-gathering+3
4839 years ago
Previous12Next