Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
sitedorks preview

sitedorks

GitHubzarcolio/sitedorks

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

dns-subdomain-enumerationinformation-gatheringosint+3
1.1k
2 days ago
noapi-google-search-mcp preview

noapi-google-search-mcp

GitHubvincentkaufmann/noapi-google-search-mcp

MCP server for Google search and page fetching using headless Chromium

anti-botcaptcha-bypasscrawler+8
1224 days ago
Ominis-OSINT preview

Ominis-OSINT

GitHubanoncatalyst/ominis-osint

Automated OSINT reconnaissance tool that queries Google and social platforms to gather intelligence on usernames and queries, with proxy rotation and…

crawlerinformation-gatheringosint+3
61114 days ago
cve-2026-13934 preview

cve-2026-13934

GitHubartwiderobo/cve-2026-13934

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

code-analysiseducationexploitation+3
15 days ago
semgrep-rules preview

semgrep-rules

GitHubelttam/semgrep-rules

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

cloud-infrastructure-securitycode-analysiscontainer-security+6
24521 days ago
google-dorks preview

google-dorks

GitHubproviesec/google-dorks

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

curated-resourcesinformation-gatheringmisconfiguration+5
1.3k26 days ago
Gemini-api-key-hunter preview

Gemini-api-key-hunter

GitHubcoffinxp/gemini-api-key-hunter
api-securitycloud-securityinformation-gathering+5
641 month ago
guardian-cli preview

guardian-cli

GitHubzakirkun/guardian-cli

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

ai-securitycloud-securityeducation+8
1.9k1 month ago
CVE-2026-11645 preview

CVE-2026-11645

GitHub0xblackash/cve-2026-11645

CVE-2026-11645

educationexploitationincident-response+3
12 months ago
MasterHttpRelayVPN-RUST preview

MasterHttpRelayVPN-RUST

GitHubtherealaleph/masterhttprelayvpn-rust

Rust port of @masterking32's MasterHttpRelayVPN — all credit to @masterking32 for the original idea and Python implementation. Free DPI bypass via a…

dns-analysisweb-security
3.6k2 months ago
ai-bot-ip-ranges preview

ai-bot-ip-ranges

GitHubrxerium/ai-bot-ip-ranges

Official IP ranges for AI bot crawlers (OpenAI, Anthropic, Google, Microsoft, Perplexity). Weekly auto-updates.

crawlercurated-resourcesdefensive-tools+2
2 months ago
CMS-Made-Simple-2.2.10---SQL-Injection preview

CMS-Made-Simple-2.2.10---SQL-Injection

GitHubjyothsna-git007/cms-made-simple-2.2.10---sql-injection

Google Dorks for detecting CMS Made Simple < 2.2.10 SQL Injection (CVE-2019-9053). Built for security auditing and patch verification.

exploitationinformation-gatheringpenetration-testing+3
2 months ago
goodoldsearch-oss preview

goodoldsearch-oss

GitHubmrtdlgc/goodoldsearch-oss
curated-resourcesdns-subdomain-enumerationeducation+6
213 months ago
CVE-2026-42897 preview

CVE-2026-42897

GitHubatiilla/cve-2026-42897

CVE-2026-42897 - Exchange Health Checker blind spot: outbound IIS URL Rewrite rules silently ignored, making EOMT mitigations invisible in diagnostic…

cloud-infrastructure-securityconfiguration-auditingeducation+3
53 months ago
Lfi-Space preview

Lfi-Space

GitHubcapture0x/lfi-space

Automated Local File Inclusion (LFI) vulnerability scanner with Google Dork search and targeted URL scan modes for web application security testing.

information-gatheringpenetration-testingvulnerability-scanners+1
1123 months ago
dorkbot preview

dorkbot

GitHubutiso/dorkbot

Command-line tool to scan Google search results for vulnerabilities

information-gatheringosintpenetration-testing+3
5483 months ago
CVE-2025-12543-Fix-for-Wildfly preview

CVE-2025-12543-Fix-for-Wildfly

GitHubkavin71725/cve-2025-12543-fix-for-wildfly
cloud-infrastructure-securitycontainer-securitydevsecops+4
4 months ago
safetext preview

safetext

GitHubgoogle/safetext

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

defensive-toolsdevsecopsscripting-automation+1
1514 months ago
Previous12345Next