Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
140 results
EvilRip preview

EvilRip

GitHubgovindpalakkal/evilrip

It is a small script to fetch out the subdomains/ip vulnerable to CVE-2020-5902 written in bash

exploitationinformation-gatheringreconnaissance+3
6
6 years ago
AISA-Scanner preview

AISA-Scanner

GitHubgmh5225/aisa-scanner

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

ai-securityexploitationpenetration-testing+6
11 year ago
react2shell preview

react2shell

GitHubtermireum/react2shell

React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE)…

exploitationpenetration-testingreconnaissance+3
7 months ago
citrixvulncheck preview

citrixvulncheck

GitHub0xams/citrixvulncheck

a script to look for CVE-2019-19781 Vulnerability within a domain and it's subdomains

exploitationreconnaissancesubdomain-enumeration+2
6 years ago
GhostTrack preview

GhostTrack

GitHubhunxbyts/ghosttrack

Useful tool to track location or mobile number

information-gatheringosintreconnaissance+1
15.0k2 years ago
KingOfBugBountyTips preview

KingOfBugBountyTips

GitHubkingofbugbounty/kingofbugbountytips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

curated-resourceseducationosint+5
5.5k1 month ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.0k2 months ago
can-i-take-over-xyz preview

can-i-take-over-xyz

GitHubedoverflow/can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

curated-resourceseducationsubdomain-enumeration+1
5.8k1 year ago
lazyrecon preview

lazyrecon

GitHubnahamsec/lazyrecon

This script is intended to automate your reconnaissance process in an organized fashion

dns-analysisinformation-gatheringpenetration-testing+3
2.0k6 years ago
datasploit preview

datasploit

GitHubdatasploit/datasploit

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

dns-subdomain-enumerationemail-harvestinginformation-gathering+6
3.3k9 months ago
SubDomainizer preview

SubDomainizer

GitHubnsonaniya2010/subdomainizer

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

cloud-securityinformation-gatheringosint+2
1.9k17 days ago
assetfinder preview

assetfinder

GitHubtomnomnom/assetfinder

Find domains and subdomains related to a given domain

dns-subdomain-enumerationinformation-gatheringosint+2
3.7k6 years ago
CF-Hero preview

CF-Hero

GitHubmusana/cf-hero

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

dns-analysisfingerprint-spoofinginformation-gathering+5
2.6k2 months ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
88922 days ago
dnsx preview

dnsx

GitHubprojectdiscovery/dnsx

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

dns-analysisdns-fuzzingdns-subdomain-enumeration+4
2.8k5 days ago
shuffledns preview

shuffledns

GitHubprojectdiscovery/shuffledns

MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy…

dns-analysisdns-fuzzingdns-subdomain-enumeration+3
1.7k7 months ago
Sudomy preview

Sudomy

GitHubscreetsec/sudomy

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

dns-analysisinformation-gatheringosint+5
2.4k2 years ago
AttackSurfaceMapper preview

AttackSurfaceMapper

GitHubsuperhedgy/attacksurfacemapper

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

information-gatheringosintreconnaissance+1
1.4k2 years ago
Previous12…8Next