Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
90 results
prowler preview

prowler

GitHubprowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+10
14.9k
10h 20m ago
serverless preview

serverless

GitHubserverless/serverless

CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local development, and multi-language…

authenticationcloud-infrastructure-securitydevsecops+4
46.9k1 day ago
kern preview

kern

GitHubgetkern/kern

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

ai-securitycloud-infrastructure-securitycontainer-security+3
4163 days ago
kali-cloud preview

kali-cloud

GitLabkalilinux/build-scripts/kali-cloud

Scripts to build Kali cloud images (fork of https://salsa.debian.org/cloud-team/debian-cloud-images)

cloud-infrastructure-securitycloud-securityscripting-automation+2
325 days ago
holos preview

holos

GitHubzeroecco/holos

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

cloud-infrastructure-securitydevsecopsgeneral-purpose-utilities+3
1455 days ago
checkov preview

checkov

GitHubbridgecrewio/checkov

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

cloud-infrastructure-securitycloud-securitycode-analysis+12
9.0k8 days ago
pybatfish preview

pybatfish

GitHubbatfish/pybatfish

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
2439 days ago
lowkey preview

lowkey

GitHubinceptionstack/lowkey

Deploy self-hosted AI coding agents (OpenClaw, Claude Code, Codex) into your AWS account with CloudFormation, IAM profiles, and sandbox isolation for…

ai-securitycloud-infrastructure-securitycloud-security+7
7112 days ago
serverless-application-model preview

serverless-application-model

GitHubaws/serverless-application-model

Transforms SAM templates into CloudFormation resources, generating Lambda functions, IAM roles, and policies with built-in serverless best practices.

cloud-infrastructure-securitycloud-securitydevsecops+1
9.6k14 days ago
psa-2026-00043-recovery preview

psa-2026-00043-recovery

GitHubdisqualifier/psa-2026-00043-recovery

Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)

cloud-infrastructure-securitydata-recoverydigital-forensics+3
22 days ago
LR-WebPKI preview

LR-WebPKI

GitHubnserser/lr-webpki

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

cloud-infrastructure-securitycryptographyeducation+2
26 days ago
policy_sentry preview

policy_sentry

GitHubsalesforce/policy_sentry

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
2.2k1 month ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
201 month ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
1 month ago
ROADtools preview

ROADtools

GitHubdirkjanm/roadtools

A collection of Azure AD/Entra tools for offensive and defensive security purposes

authenticationcloud-infrastructure-securitycloud-security+5
2.7k1 month ago
CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation preview

CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation

GitHubgeorge0papasotiriou/cve-2026-21019-kubernetes-cronjob-suspended-execution-via-time-manipulation

Reproduces CVE-2026-21019 by manipulating node clock to force early Kubernetes CronJob execution; includes vulnerable YAML manifest and Python…

adversarial-attackcloud-infrastructure-securitycloud-security+3
1 month ago
CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath preview

CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath

GitHubgeorge0papasotiriou/cve-2026-21008-kubernetes-service-account-token-mounted-in-hostpath

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

cloud-infrastructure-securitycloud-securitycontainer-security+4
1 month ago
CVE-2026-5556-Kubernetes-Admission-Controller-Bypass-via-Case-Sensitivity preview

CVE-2026-5556-Kubernetes-Admission-Controller-Bypass-via-Case-Sensitivity

GitHubgeorge0papasotiriou/cve-2026-5556-kubernetes-admission-controller-bypass-via-case-sensitivity

Exploit PoC and vulnerable admission webhook for CVE-2026-5556, demonstrating Kubernetes admission controller bypass via case-sensitive pod name…

adversarial-attackcloud-infrastructure-securitycloud-security+4
1 month ago
Previous12345Next