Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
natlas preview

natlas

GitHubnatlas/natlas

Attack Surface Management since before Attack Surface Management was a thing

cloud-infrastructure-securityinformation-gatheringnetwork-mapping+2
6607 months ago
aws_public_ips preview

aws_public_ips

GitHubarkadiyt/aws_public_ips

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

cloud-infrastructure-securitycloud-securityinformation-gathering+1
6426 years ago
nuvola preview

nuvola

GitHubprimait/nuvola

Graph-based AWS security analysis tool that dumps cloud configurations, detects misconfigurations, and maps attack paths using a Neo4j digital twin…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
14418 days ago
BlobHunter preview

BlobHunter

GitHubcyberark/blobhunter

Find exposed data in Azure with this public blob scanner

cloud-infrastructure-securitycloud-securityinformation-gathering+2
3592 years ago
Aaia preview

Aaia

GitHubrams3sh/aaia

AWS Identity and Access Management Visualizer and Anomaly Finder

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
2972 years ago
BucketLoot preview

BucketLoot

GitHubredhuntlabs/bucketloot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

cloud-infrastructure-securitycloud-securityinformation-gathering+4
4459 months ago
check_mdi preview

check_mdi

GitHubexpl0itabl3/check_mdi

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

cloud-infrastructure-securitycloud-securityinformation-gathering+2
2241 year ago
nixos-config preview

nixos-config

GitHubxddxdd/nixos-config

Lan Tian's NixOS Configuration

cloud-infrastructure-securityconfiguration-auditingcryptography+6
1363h 47m ago
vc5 preview

vc5

GitHubdavidcoles/vc5

A horizontally scalable Direct Server Return layer 4 load balancer for Linux using XDP/eBPF

cloud-infrastructure-securitydevsecopsdns-analysis+1
1261 month ago
CMLoot preview

CMLoot

GitHub1njected/cmloot

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares

cloud-infrastructure-securityinformation-gatheringpenetration-testing+2
1983 years ago
Thunderstorm preview

Thunderstorm

GitHubustayready/thunderstorm

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+7
8317 days ago
aad-bofs preview

aad-bofs

GitHubkozmer/aad-bofs

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

adversarial-attackcloud-infrastructure-securitycloud-security+5
14110 months ago
netfence preview

netfence

GitHubdanthegoodman1/netfence

Like Envoy xDS, but for eBPF filters

cloud-infrastructure-securitycloud-securitycontainer-security+5
10214 days ago
CanaryHunter preview

CanaryHunter

GitHubc0axx/canaryhunter

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

adversarial-attackcloud-infrastructure-securityconfiguration-auditing+4
1363 years ago
slurp-old preview

slurp-old

GitHub0xbharath/slurp-old

A tool to enumerate S3 buckets manually or via certstream

cloud-infrastructure-securitycloud-securityinformation-gathering+3
843 years ago
s3_objects_check preview

s3_objects_check

GitHubnccgroup/s3_objects_check

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
774 years ago
SCOPE preview

SCOPE

GitHubtayontech/scope

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

ai-securitycloud-infrastructure-securitycloud-security+8
543 months ago
AzureADEnumeration preview

AzureADEnumeration

GitHublogisek/azureadenumeration

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

cloud-infrastructure-securitycloud-securitydns-analysis+6
808 months ago
Previous1234Next