Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
276 results
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

fingerprint-spoofinginformation-gatheringosint+6
886
17 days ago
Recheck preview

Recheck

GitHubtegal1337/recheck

Deep scan domain and find all possible domain to takeover

dns-subdomain-enumerationreconnaissancesubdomain-enumeration+1
173 years ago
omnisci3nt preview

omnisci3nt

GitHubspyboy-productions/omnisci3nt

Unified web reconnaissance toolkit for automated domain intelligence, including subdomain discovery, DNS enumeration, port scanning, SSL inspection,…

dns-analysisinformation-gatheringosint+6
3682 months ago
Garud preview

Garud

GitHubr0x4r/garud

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

penetration-testingreconnaissancesubdomain-enumeration+2
8113 months ago
second-order preview

second-order

GitHubmhmdiaa/second-order

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

crawlerreconnaissancesubdomain-enumeration+2
4081 year ago
scriptkiddi3 preview

scriptkiddi3

GitHubthecyberneh/scriptkiddi3

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

penetration-testingreconnaissancesubdomain-enumeration+1
1522 years ago
citrixvulncheck preview

citrixvulncheck

GitHub0xams/citrixvulncheck

a script to look for CVE-2019-19781 Vulnerability within a domain and it's subdomains

exploitationreconnaissancesubdomain-enumeration+2
6 years ago
karma_v2 preview

karma_v2

GitHubdheerajmadhukar/karma_v2

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

crawlerdns-subdomain-enumerationinformation-gathering+4
1.0k2 years ago
sub404 preview
Archived

sub404

GitHubr3curs1v3-pr0xy/sub404

A python tool to check subdomain takeover vulnerability

dns-analysispenetration-testingreconnaissance+3
3533 years ago
ghostbuster preview

ghostbuster

GitHubassetnote/ghostbuster

Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.

cloud-securitydns-analysisreconnaissance+2
2781 year ago
CVE-2020-5902-Scanner preview

CVE-2020-5902-Scanner

GitHubpushpenderindia/cve-2020-5902-scanner

Automated scanner for F5 BIG-IP CVE-2020-5902, detecting and exploiting remote code execution and local file inclusion vulnerabilities in TMUI.

exploitationreconnaissancesubdomain-enumeration+2
124 years ago
-CVE-2023-30845 preview

-CVE-2023-30845

GitHubhimori123/-cve-2023-30845

Automated exploit script for CVE-2023-30845 that scans and tests multiple subdomains for the vulnerability, enabling rapid security assessment.

exploitationreconnaissancesubdomain-enumeration+2
162 years ago
CVE-2020-13942-POC- preview

CVE-2020-13942-POC-

GitHubshifa123/cve-2020-13942-poc-

Automated proof-of-concept exploit for CVE-2020-13942 with integrated subdomain enumeration and batch vulnerability scanning for bug bounty programs.

exploitationreconnaissancesubdomain-enumeration+2
95 years ago
PY-Log4j-RCE-Scanner preview

PY-Log4j-RCE-Scanner

GitHubmrharshvardhan/py-log4j-rce-scanner

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

dns-analysisexploitationreconnaissance+3
43 years ago
ore_react2shell_scanner preview

ore_react2shell_scanner

GitHubrapticore/ore_react2shell_scanner

Automated scanner for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Features async endpoint discovery, subdomain…

exploitationpenetration-testingreconnaissance+4
25 months ago
react2shell preview

react2shell

GitHubtermireum/react2shell

Go-based vulnerability scanner for detecting Server-Side RCE in Next.js applications. Features automated subdomain reconnaissance via Subfinder and…

exploitationpenetration-testingreconnaissance+3
7 months ago
subdomain-tko preview

subdomain-tko

GitHubrandomrobbiebf/subdomain-tko

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

dns-analysisreconnaissancesubdomain-enumeration+2
6 years ago
OSINT-Framework preview

OSINT-Framework

GitHublockfale/osint-framework

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

curated-resourcesdns-subdomain-enumerationeducation+8
12.0k4 months ago
Previous12…16Next