Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
kubeshark preview

kubeshark

GitHubkubeshark/kubeshark

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

ai-securitycloud-infrastructure-securitycloud-security+9
12.1k
4 days ago
bucketbuster preview

bucketbuster

GitHubooafa/bucketbuster

Scans public cloud object-storage endpoints across Yandex, VK, Selectel, Sber, Alibaba, Tencent, Huawei, and Baidu to find listable buckets and…

cloud-infrastructure-securitycloud-securitydata-exfiltration+6
25 days ago
mailcow-dockerized preview

mailcow-dockerized

GitHubmailcow/mailcow-dockerized

Dockerized mail server suite with Postfix, Dovecot, Rspamd, and ClamAV. Provides secure email hosting with integrated spam filtering, antivirus, and…

authenticationcloud-infrastructure-securityconfiguration-auditing+4
13.5k7 days ago
Thunderstorm preview

Thunderstorm

GitHubustayready/thunderstorm

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+7
8013 days ago
nuvola preview

nuvola

GitHubprimait/nuvola

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
14413 days ago
graph-go preview

graph-go

GitHubguilherme-grimm/graph-go

simply nodes and graphs

cloud-infrastructure-securityconfiguration-auditingcontainer-security+4
1271 month ago
cloudfox preview

cloudfox

GitHubbishopfox/cloudfox

Automating situational awareness for cloud penetration tests.

cloud-infrastructure-securitycloud-securityexploitation+7
2.6k1 month ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
341 month ago
ROADtools preview

ROADtools

GitHubdirkjanm/roadtools

A collection of Azure AD/Entra tools for offensive and defensive security purposes

authenticationcloud-infrastructure-securitycloud-security+5
2.7k1 month ago
Azure preview

Azure

GitHuboffsecpierogi/azure

Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+8
12 months ago
MicroBurst preview

MicroBurst

GitHubnetspi/microburst

A collection of scripts for assessing Microsoft Azure security

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
2.4k3 months ago
SCOPE preview

SCOPE

GitHubtayontech/scope

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

ai-securitycloud-infrastructure-securitycloud-security+8
543 months ago
cirro-azcli-ext preview

cirro-azcli-ext

GitHubbishopfox/cirro-azcli-ext

Azure CLI extension for Cirro collection

cloud-infrastructure-securitycloud-securityinformation-gathering+3
85 months ago
Dop2Mop preview

Dop2Mop

GitHubh4wkst3r/dop2mop

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

cloud-infrastructure-securitycloud-securitycontainer-security+8
45 months ago
pacu preview

pacu

GitHubrhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

cloud-infrastructure-securitycloud-securitydata-exfiltration+7
5.3k6 months ago
sdwan-scanner-CVE-2026-20127 preview

sdwan-scanner-CVE-2026-20127

GitHubabrahamsurf/sdwan-scanner-cve-2026-20127

Cisco SD-WAN Exposure & Potential Vulnerability Scanner (Passive Fingerprinting) 2026

cloud-infrastructure-securityinformation-gatheringnetwork-security+3
6 months ago
anteon preview

anteon

GitHubgetanteon/anteon

eBPF-powered Kubernetes monitoring and performance testing platform that automatically generates service maps, tracks real-time metrics, and runs…

cloud-infrastructure-securitycontainer-security
8.5k6 months ago
natlas preview

natlas

GitHubnatlas/natlas

Attack Surface Management since before Attack Surface Management was a thing

cloud-infrastructure-securityinformation-gatheringnetwork-mapping+2
6606 months ago
Previous123Next