Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k
2 months ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.3k1 month ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
1 month ago
SiteBroker preview
Archived

SiteBroker

GitHubanon-exploiter/sitebroker

A cross-platform python based utility for information gathering and penetration testing automation!

crawlerdns-analysisinformation-gathering+5
4302 years ago
jsubfinder preview

jsubfinder

GitHubthreatunknown/jsubfinder

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

information-gatheringosintreconnaissance+3
2831 year ago
PCWT preview

PCWT

GitHubascr0b/pcwt

Web-based project management interface for penetration testing and bug bounty workflows, automating port scanning with Nmap/Masscan and subdomain…

information-gatheringpenetration-testingpenetration-testing-frameworks+5
455 years ago
domain-to-webapp preview

domain-to-webapp

GitHubcyberblackhole/domain-to-webapp

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

information-gatheringpenetration-testingreconnaissance+2
57 years ago
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

api-securityapi-security-testingdynamic-code-analysis+14
5.6k2 days ago
WAES preview

WAES

GitHubshiva108/waes

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

ctfeducationinformation-gathering+7
708 months ago
pentx-vapt-skill preview

pentx-vapt-skill

GitHubyashas-13/pentx-vapt-skill

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC

exploitationinformation-gatheringpenetration-testing+6
21 month ago
haxunit preview

haxunit

GitHubbandit-haxunit/haxunit

Automated web domain reconnaissance and security assessment tool integrating subdomain enumeration, port scanning, vulnerability scanning, and…

ai-securitycrawlerfuzzing+7
3311 year ago
Spartan preview

Spartan

GitHubmad-robot/spartan

Automated reconnaissance framework integrating subdomain enumeration, live host probing, port scanning, CMS detection, and directory brute-forcing…

information-gatheringpenetration-testingport-scanning+3
1915 years ago
subjack preview

subjack

GitHubhaccer/subjack

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

dns-analysispenetration-testingsubdomain-enumeration+2
2.1k6 months ago
tko-subs preview

tko-subs

GitHubanshumanbh/tko-subs

A tool that can help detect and takeover subdomains with dead DNS records

cloud-securitydns-analysispenetration-testing+2
7735 years ago
Garud preview

Garud

GitHubr0x4r/garud

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

penetration-testingreconnaissancesubdomain-enumeration+2
8105 months ago
Subhunter preview

Subhunter

GitHubumutcamliyurt/subhunter

Fast subdomain takeover scanner that checks DNS CNAME records against known fingerprints to detect vulnerable subdomains. Built in Go with…

penetration-testingsubdomain-enumerationvulnerability-scanners+1
884 months ago
scriptkiddi3 preview

scriptkiddi3

GitHubthecyberneh/scriptkiddi3

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

penetration-testingreconnaissancesubdomain-enumeration+1
1522 years ago
AISA-Scanner preview

AISA-Scanner

GitHubgmh5225/aisa-scanner

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

ai-securityexploitationpenetration-testing+6
11 year ago
Previous123Next