Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
rdap preview

rdap

GitHubopenrdap/rdap

RDAP command line client

dns-analysisinformation-gatheringnetwork-mapping+3
4141 day ago
cplt preview

cplt

GitHubnavikt/cplt

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

ai-securitycommand-and-controlconfiguration-auditing+7
1212 days ago
dnsx preview

dnsx

GitHubprojectdiscovery/dnsx

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

dns-analysisdns-fuzzingdns-subdomain-enumeration+4
2.9k4 days ago
zdns preview

zdns

GitHubzmap/zdns

Fast DNS Lookup Library and CLI Tool

dns-analysisinformation-gatheringnetwork-security+2
1.1k5 days ago
webanalyze preview

webanalyze

GitHubrverton/webanalyze

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

crawlerinformation-gatheringosint+3
1.2k6 days ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
186 days ago
Responsible-Alliance-Protocol preview

Responsible-Alliance-Protocol

GitHubphilippeabraxas-jpg/responsible-alliance-protocol

Safety cannot be a prompt instruction. TBP provides an external execution-layer boundary for autonomous agents, enforcing hard F/I/W invariants via…

ai-securityauthentication-authorizationconfiguration-auditing+7
10 days ago
Hundred OSINT preview

Hundred OSINT

GitLabt-beckett/h-osint

Local-first, keyboard-driven OSINT workbench for the terminal with 28 modules covering username, domain, IP, email, breach, and geolocation lookups…

dns-analysiseducationemail-harvesting+7
14 days ago
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.4k14 days ago
grdpwasm preview

grdpwasm

GitHubnakagami/grdpwasm

A web-based RDP client

authenticationencryption-decryption-toolsnetwork-security+3
3201 month ago
vault-conductor preview

vault-conductor

GitHubpirafrank/vault-conductor

An SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager

authenticationcloud-securitydevsecops+3
391 month ago
neko-master preview

neko-master

GitHubforu17/neko-master

A modern and elegant dashboard for network traffic visualization and analysis.

information-gatheringlog-analysisnetwork-mapping+3
4.1k1 month ago
wardn preview

wardn

GitHubrohansx/wardn

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

api-securityauthentication-authorizationcloud-security+6
362 months ago
reconvault preview

reconvault

GitHubparbatzone/reconvault

🔍 Recon notes organizer for bug bounty hunters and CTF players — subdomains, ports, endpoints, vulns, all in one place.

ctfeducationinformation-gathering+6
12 months ago
rmm preview

rmm

GitHubalevsk/rmm

Recon MindMap (RMM)

information-gatheringpenetration-testingreconnaissance+1
1852 months ago
bepr preview

bepr

GitHubaperocky/bepr

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

authenticationcommand-and-controlpenetration-testing+3
3 months ago
pompelmi preview

pompelmi

GitHubpompelmi/pompelmi

ClamAV antivirus scanning for Node.js — scan file uploads with a single function call. Zero dependencies. Typed Symbol verdicts. Local or…

api-securitycloud-securitycontainer-security+6
6774 months ago
buyer-eval-skill preview

buyer-eval-skill

GitHubsalespeak-ai/buyer-eval-skill

B2B software vendor evaluation skill for Claude Code — domain-expert questions, vendor AI agent conversations, evidence-based scoring

ai-securitycurated-resourceseducation+8
694 months ago
Previous12Next