Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
spire preview

spire

GitHubspiffe/spire

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

authenticationauthentication-authorizationcloud-infrastructure-security+5
2.5k
18h 16m ago
opa preview

opa

GitHubopen-policy-agent/opa

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

api-securityauthenticationauthentication-authorization+10
12.2k22h 26m ago
warpgate preview

warpgate

GitHubwarp-tech/warpgate

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

authentication-authorizationcloud-infrastructure-securitydatabase-security+4
7.7k3 days ago
headscale preview

headscale

GitHubjuanfont/headscale

An open source, self-hosted implementation of the Tailscale control server

authentication-authorizationcloud-infrastructure-securityidentity-access-management+2
43.5k4 days ago
aws-iam-authenticator preview

aws-iam-authenticator

GitHubkubernetes-sigs/aws-iam-authenticator

A tool to use AWS IAM credentials to authenticate to a Kubernetes cluster

authentication-authorizationcloud-infrastructure-securitycloud-security+1
2.3k6 days ago
CVE-2026-58073-check preview

CVE-2026-58073-check

GitHubbishopfox/cve-2026-58073-check

Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073

cloud-infrastructure-securitynetwork-securitypenetration-testing+2
7 days ago
boundary preview

boundary

GitHubhashicorp/boundary

Boundary enables identity-based access management for dynamic infrastructure.

authentication-authorizationcloud-infrastructure-securityidentity-access-management+1
4.1k26 days ago
dex preview

dex

GitHubdexidp/dex

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

authenticationauthentication-authorizationcloud-infrastructure-security+4
11.1k27 days ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
1827 days ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
27 days ago
CVE-2026-5556-Kubernetes-Admission-Controller-Bypass-via-Case-Sensitivity preview

CVE-2026-5556-Kubernetes-Admission-Controller-Bypass-via-Case-Sensitivity

GitHubgeorge0papasotiriou/cve-2026-5556-kubernetes-admission-controller-bypass-via-case-sensitivity

Exploit PoC and vulnerable admission webhook for CVE-2026-5556, demonstrating Kubernetes admission controller bypass via case-sensitive pod name…

adversarial-attackcloud-infrastructure-securitycloud-security+4
1 month ago
auth preview

auth

GitHubplaceos/auth

PlaceOS authentication service and API gatekeeper.

api-securityauthentication-authorizationcloud-infrastructure-security+2
22 months ago
zttp preview

zttp

GitLabnihal799/zttp

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

authentication-authorizationcloud-infrastructure-securitydefensive-tools+3
2 months ago
bmcweb preview

bmcweb

GitHubopenbmc/bmcweb

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

api-securityauthentication-authorizationcloud-infrastructure-security+6
2353 months ago
azpim preview

azpim

GitHubtapanmeena/azpim

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

authentication-authorizationcloud-infrastructure-securitycloud-security+3
65 months ago
safenet-soho-security-framework preview

safenet-soho-security-framework

GitHubalvin-alvo/safenet-soho-security-framework

A lightweight, policy-driven framework that brings Zero-Trust micro-segmentation to SOHO networks using WireGuard.

authentication-authorizationcloud-infrastructure-securityencryption-decryption-tools+1
25 months ago
ephemera preview

ephemera

GitHubqarait/ephemera

Zero-Trust SSH CA

authentication-authorizationcloud-infrastructure-securityconfiguration-auditing+6
296 months ago
CertificateDsc preview

CertificateDsc

GitHubdsccommunity/certificatedsc

DSC resources to simplify administration of certificates on a Windows Server.

authentication-authorizationcloud-infrastructure-securityconfiguration-auditing+3
1257 months ago
Previous12Next