Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
997 results
dnsReaper preview

dnsReaper

GitHubpunk-security/dnsreaper

Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

cloud-securitydevsecopsdns-analysis+2
2.2k
10 months ago
Subrake preview

Subrake

GitHubhash3lizer/subrake

🚀 A DNS automated scanner and tool 🖱️ (Zone Transfer, DNS Zone Takeover, Subdomain Takeover).

dns-analysisdns-subdomain-enumerationinformation-gathering+4
3003 years ago
Myesve preview

Myesve

GitHubnyakki-labs-0x420/myesve

CVE-2024-38475 exploitation & scanning tool with Mullvad VPN rotation

exploitationinformation-gatheringpenetration-testing+5
2 months ago
wp2shell-scanner preview

wp2shell-scanner

GitHubhidden-investigations/wp2shell-scanner

WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.

exploitationinformation-gatheringpayload-generation+3
11 month ago
wprecon preview

wprecon

GitHubffx64/wprecon

WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.

information-gatheringpenetration-testingreconnaissance+2
204 months ago
3klCon preview
Archived

3klCon

GitHubeslam3kl/3klcon

Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.

information-gatheringpenetration-testingport-scanning+3
6892 years ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.0k1 month ago
Reconnoitre preview

Reconnoitre

GitHubcodingo/reconnoitre

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+4
2.2k6 years ago
cloudfrunt preview

cloudfrunt

GitHubmindpointgroup/cloudfrunt

A tool for identifying misconfigured CloudFront domains

cloud-securitydns-subdomain-enumerationmisconfiguration+1
3618 years ago
Project-Eyes-On preview

Project-Eyes-On

GitHuby0oshi/project-eyes-on

Project Eyes On is a high-speed, multi-threaded surveillance tool by Y0oshi (@rde0) for locating open IP cameras worldwide. Unifies Google Dorking…

crawlerdns-subdomain-enumerationinformation-gathering+4
2237 months ago
LHF preview

LHF

GitHubblindfuzzy/lhf

A modular recon tool for pentesting

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+4
2759 years ago
attack-surface-framework preview

attack-surface-framework

GitHubvmware-labs/attack-surface-framework

Tool to discover external and internal network attack surface

dns-subdomain-enumerationexploitationinformation-gathering+8
2062 years ago
wosind preview

wosind

GitHubwhitelisthackers/wosind

An OSINT tool for collecting public information.

dns-analysisdns-subdomain-enumerationemail-harvesting+7
106 years ago
AutoSQLi preview
Archived

AutoSQLi

GitHubclouedoc/autosqli

An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.

dns-subdomain-enumerationosintpenetration-testing+3
2715 years ago
kanha preview

kanha

GitHubpwnwriter/kanha

🦚 A web-app pentesting suite written in rust .

dns-subdomain-enumerationfuzzinginformation-gathering+5
3241 year ago
urlbrute preview

urlbrute

GitHubreddyyz/urlbrute

Directory/Subdomain scanner developed in GoLang.

dns-subdomain-enumerationinformation-gatheringvulnerability-scanners+1
485 years ago
mongobleed-scanner preview

mongobleed-scanner

GitHubpedrocruz2202/mongobleed-scanner

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

database-securityexploitationinformation-gathering+3
4 days ago
CVE-2017-9841 preview

CVE-2017-9841

GitHubmrg3p5/cve-2017-9841

A Tool for scanning CVE-2017-9841 with multithread

exploitationinformation-gatheringpenetration-testing+2
42 years ago
Previous12…56Next