Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
224 results
react2shell preview

react2shell

GitHubtermireum/react2shell

React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE)…

exploitationpenetration-testingreconnaissance+3
7 months ago
awesome-bugbounty-tools preview

awesome-bugbounty-tools

GitHubvavkamil/awesome-bugbounty-tools

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

curated-resourcesexploitationfuzzing+5
6.2k1 day ago
Subhunter preview

Subhunter

GitHubumutcamliyurt/subhunter

Fast subdomain takeover scanner that checks DNS CNAME records against known fingerprints to detect vulnerable subdomains. Built in Go with…

penetration-testingsubdomain-enumerationvulnerability-scanners+1
883 months ago
CVE-2025-55182-Simple-Scanner-main preview

CVE-2025-55182-Simple-Scanner-main

GitHubjan0x190/cve-2025-55182-simple-scanner-main

Multi-language scanner for CVE-2025-55182 RCE in Next.js React Server Components, with single/mass scanning modes and integrated bug bounty…

educationexploitationpenetration-testing+4
18 months ago
subjack preview

subjack

GitHubhaccer/subjack

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

dns-analysispenetration-testingsubdomain-enumeration+2
2.1k5 months ago
PAVELOW preview

PAVELOW

GitHuboffxec/pavelow

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…

exploit-frameworksinformation-gatheringosint+7
908 years ago
frontpage-server-extensions-vulnerability-scanner preview

frontpage-server-extensions-vulnerability-scanner

GitHubjosekutty-k/frontpage-server-extensions-vulnerability-scanner

Python script to scan for CVE-2000-0114 vulnerability in Frontpage Server Extensions. Automates subdomain enumeration and vulnerability scanning…

educationpenetration-testingreconnaissance+3
2 years ago
Garud preview

Garud

GitHubr0x4r/garud

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

penetration-testingreconnaissancesubdomain-enumeration+2
8103 months ago
rapidscan preview

rapidscan

GitHubskavngr/rapidscan

:new: The Multi-Tool Web Vulnerability Scanner.

dns-analysisinformation-gatheringpenetration-testing+5
2.1k3 years ago
BlackDir-Framework preview

BlackDir-Framework

GitHubjehadalqurashi/blackdir-framework

Web Application Vulnerability Scanner

encryption-decryption-toolshash-analysisinformation-gathering+5
1375 years ago
r3con preview

r3con

GitHubthenurhabib/r3con

Multi-functional Web Recon & Vulnerability Scanner Tool

crawlerdns-analysisinformation-gathering+5
344 years ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.0k5h 42m ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
89027 days ago
RED_HAWK preview

RED_HAWK

GitHubtuhinshubhra/red_hawk

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

crawlerdns-analysisinformation-gathering+5
3.7k5 years ago
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

api-securityapi-security-testingdynamic-code-analysis+14
5.5k20h 50m ago
Striker preview

Striker

GitHubs0md3v/striker

Striker is an offensive information and vulnerability scanner.

information-gatheringport-scanningreconnaissance+3
2.3k7 years ago
DarkAngel preview

DarkAngel

GitHubbywalks/darkangel

Automated white-hat vulnerability scanner that monitors HackerOne and Bugcrowd assets, performs subdomain enumeration, crawling, fingerprinting, and…

crawlerinformation-gatheringpenetration-testing+3
6073 years ago
Eagle preview

Eagle

GitHubbitthebyte/eagle

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

exploitationinformation-gatheringmisconfiguration+4
1285 years ago
Previous12…13Next