Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k
2 years ago
safe-chain preview

safe-chain

GitHubaikidosec/safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

defensive-toolsdevsecopsmalware-analysis+3
1.7k3 days ago
rengine preview

rengine

GitHubyogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

crawlerdns-subdomain-enumerationinformation-gathering+9
8.8k9 months ago
ghauri preview

ghauri

GitHubr0oth3x49/ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

database-securitypenetration-testingvulnerability-scanners+2
4.1k10 months ago
CMSmap preview

CMSmap

GitHubdionach/cmsmap

CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

information-gatheringvulnerability-scannersweb-security
1.2k7 years ago
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
32525 days ago
Nightingale preview

Nightingale

GitHubrajanagori/nightingale

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

container-securityeducationforensics+7
3131 month ago
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1495 months ago
webdiscover preview

webdiscover

GitHubv1n1v131r4/webdiscover

The purpose of this script is to automate the web enumeration process and search for exploits

exploit-frameworksreconnaissancevulnerability-scanners+1
1164 years ago
lazyrecon preview

lazyrecon

GitHubjhaddix/lazyrecon

This script is intended to automate your reconnaissance process in an organized fashion

information-gatheringnetwork-mappingpenetration-testing+4
478 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xwhoknows/cve-2025-29927

Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save…

exploitationinformation-gatheringpenetration-testing+3
31 year ago
xz-utils-vuln-checker preview

xz-utils-vuln-checker

GitHubharekrishnarai/xz-utils-vuln-checker

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…

curated-resourceseducationsupply-chain-security+2
12 years ago
G3-Loop-DoS preview

G3-Loop-DoS

GitHubrenancesarr/g3-loop-dos

This Python script automates the process of scanning for systems potentially vulnerable to the Loop DoS attack and the hypothetical CVE-2024-2169…

educationexploitationnetwork-security+2
2 years ago
CVE-2024-9326-PoC preview

CVE-2024-9326-PoC

GitHubghostwirez/cve-2024-9326-poc

This PoC script is designed to verify the presence of CVE-2024-9326, a high SQL Injection vulnerability in PHPGurukul Online Shopping Portal v2.0. It…

exploitationpenetration-testingvulnerability-analysis+3
1 year ago
MagicArch preview

MagicArch

GitLabmagicbytes/magicarch

MagicArch is a comprehensive post-installation script built with Ansible, designed to transform a basic Arch Linux installation into a fully equipped…

exploit-frameworksforensicsinformation-gathering+8
22 years ago
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

database-securityexploitationpenetration-testing+2
38.2k15h 50m ago
Argus preview

Argus

GitHubjasonxtn/argus

The Ultimate Information Gathering Toolkit

crawlerdns-analysisemail-harvesting+7
4.1k8 months ago
nmapAutomator preview

nmapAutomator

GitHub21y4d/nmapautomator

A script that you can run in the background!

information-gatheringnetwork-mappingpenetration-testing+3
3.1k5 years ago
Previous123Next