Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
evildork preview

evildork

GitHubfricciolosa-red-team/evildork

Automated Google dorking tool for extracting leaked secrets, personal information, and subdomains from a target domain or individual, outputting…

dns-subdomain-enumerationinformation-gatheringosint+2
95
3 years ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
26 days ago
openshield preview

openshield

GitHubowasp/openshield

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

cloud-securityconfiguration-auditingcryptography+4
562 days ago
gh-dork preview

gh-dork

GitHubmolly/gh-dork

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

information-gatheringosintreconnaissance+2
1374 years ago
SMWYG-Show-Me-What-You-Got preview

SMWYG-Show-Me-What-You-Got

GitHubviralmaniar/smwyg-show-me-what-you-got

This tool allows you to perform OSINT and reconnaissance on an organisation or an individual. It allows one to search 1.4 Billion clear text…

information-gatheringosintpassword-cracking+1
5737 years ago
Invoke-WCMDump preview

Invoke-WCMDump

GitHubpeewpw/invoke-wcmdump

PowerShell Script to Dump Windows Credentials from the Credential Manager

information-gatheringpassword-crackingpenetration-testing+2
7328 years ago
zizzania preview

zizzania

GitHubcyrus-and/zizzania

Automated DeAuth attack

information-gatheringpenetration-testingwi-fi-auditing+1
3202 years ago
nuclei-wordfence-cve preview

nuclei-wordfence-cve

GitHubtopscoder/nuclei-wordfence-cve

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

crawlerexploitationinformation-gathering+3
1.3k5h 7m ago
RED_HAWK preview

RED_HAWK

GitHubtuhinshubhra/red_hawk

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

crawlerdns-analysisinformation-gathering+5
3.8k6 years ago
EagleEye preview

EagleEye

GitHubthoughtfuldev/eagleeye

Stalk your Friends. Find their Instagram, FB and Twitter Profiles using Image Recognition and Reverse Image Search.

information-gatheringmachine-learningosint+3
5.2k4 years ago
Rock-ON preview

Rock-ON

GitHubsilverpoision/rock-on

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

crawlerdns-subdomain-enumerationinformation-gathering+5
2906 years ago
GitMonitor preview

GitMonitor

GitHubtalkaboutcybersecurity/gitmonitor

One way to continuously monitor sensitive information that could be exposed on Github

information-gatheringosintreconnaissance+1
1726 years ago
bugsy preview

bugsy

GitHubmobb-dev/bugsy

Automatic security vulnerability remediation for your code.

ai-securitycode-analysisdevsecops+2
6918 days ago
dnsmap preview

dnsmap

GitHubmakefu/dnsmap

fork of http://code.google.com/p/dnsmap/source/checkout

dns-subdomain-enumerationinformation-gatheringpenetration-testing+1
1189 years ago
SSH-Snake preview
Archived

SSH-Snake

GitHubmegamansec/ssh-snake

SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.

information-gatheringlateral-movementnetwork-mapping+5
2.3k5 months ago
PentestBro preview

PentestBro

GitHubmarius-rothenbuecher/pentestbro

Windows-based reconnaissance tool combining subdomain enumeration, port scanning, banner grabbing, whois lookups, and web path enumeration for…

information-gatheringpenetration-testingport-scanning+3
605 years ago
nelson preview

nelson

GitHubswelljoe/nelson

Finding vulnerabilities through dumb brute force

ai-securitycode-analysiseducation+3
551 month ago
Sububy preview

Sububy

GitHuba3h1nt/sububy

Modular subdomain enumeration suite with certificate transparency, DNS brute-force, and API-based discovery. Includes post-enumeration modules for…

dns-subdomain-enumerationinformation-gatheringosint+2
71 year ago
Previous12Next