Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5129 results
evine preview

evine

GitHubsaeeddhqan/evine

Interactive CLI Web Crawler

crawlerinformation-gatheringosint+2
1813 months ago
I-know-where-your-page-lives preview

I-know-where-your-page-lives

GitHubioactive/i-know-where-your-page-lives

I Know Where Your Page Lives: Derandomizing the latest Windows 10 Kernel - ZeroNights 2016

adversarial-attackexploitationinformation-gathering+1
1759 years ago
sub.Monitor preview

sub.Monitor

GitHube1abrador/sub.monitor

Self-hosted passive subdomain continous monitoring tool.

information-gatheringreconnaissancesubdomain-enumeration
1722 years ago
SocialPath preview

SocialPath

GitHubwoj-ciech/socialpath

OSINT tool to track and correlate user identities across multiple social media platforms using username search, API integrations, and deanonymization…

information-gatheringosintreconnaissance+1
1695 years ago
creds.py preview

creds.py

GitHubdanmcinerney/creds.py

Harvest FTP/POP/IMAP/HTTP/IRC creds

information-gatheringnetwork-securityosint+3
16811 years ago
profilehound preview

profilehound

GitHubm4lwhere/profilehound

ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets by…

information-gatheringlateral-movementosint+4
1644 months ago
massh-enum preview

massh-enum

GitHubtrimstray/massh-enum

OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).

exploitationinformation-gatheringnetwork-security+3
1596 years ago
censys-enumeration preview

censys-enumeration

GitHub0xbharath/censys-enumeration

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys

email-harvestinginformation-gatheringosint+2
1563 years ago
SMBSR preview

SMBSR

GitHuboldboy21/smbsr

Lookup for interesting stuff in SMB shares

information-gatheringnetwork-securityosint+2
1503 years ago
hfinger preview

hfinger

GitHubcert-polska/hfinger

Generates unique fingerprints of malware HTTP requests from pcap files using Tshark, enabling identification and grouping of malware families through…

information-gatheringmalware-analysisthreat-intelligence
1483 years ago
ffufw preview

ffufw

GitHubpuzzlepeaches/ffufw

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

fuzzinginformation-gatheringpenetration-testing+2
1476 months ago
uddup preview

uddup

GitHubrotemreiss/uddup

Urls de-duplication tool for better recon.

information-gatheringreconnaissanceutilities-frameworks+1
1455 months ago
ParaForge preview

ParaForge

GitHubanof-cyber/paraforge

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

fuzzinginformation-gatheringpenetration-testing+1
1423 years ago
melody preview
Archived

melody

GitHubma111e/melody

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

information-gatheringintrusion-detectionnetwork-security+5
1391 year ago
jsfinder preview

jsfinder

GitHubkacakb/jsfinder

Fetches JavaScript files quickly and comprehensively.

crawlerinformation-gatheringreconnaissance+1
1383 years ago
SCMKit preview

SCMKit

GitHubxforcered/scmkit

Source Code Management Attack Toolkit

information-gatheringpenetration-testingpersistence-mechanisms+4
1343 years ago
BurpParamFlagger preview

BurpParamFlagger

GitHuballyomalley/burpparamflagger

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

information-gatheringpenetration-testingvulnerability-scanners+2
1345 years ago
azbelt preview

azbelt

GitHubdaddycocoaman/azbelt

AAD related enumeration in Nim

authenticationcloud-securityidentity-access-management+5
1323 years ago
Previous1…939495…100Next