Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
cloudquery preview

cloudquery

GitHubcloudquery/cloudquery

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
6.5k16h 51m ago
azurelinux preview

azurelinux

GitHubmicrosoft/azurelinux

Hardened, Azure-optimized Linux distribution built from Fedora sources with RPM packaging, supply chain security, and declarative configuration for…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+4
5.3k2 days ago
vcenter_saml_login preview

vcenter_saml_login

GitHubhorizon3ai/vcenter_saml_login

A tool to extract the IdP cert from vCenter backups and log in as Administrator

authentication-authorizationcloud-infrastructure-securityexploitation+4
5292 years ago
pybatfish preview

pybatfish

GitHubbatfish/pybatfish

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
24220 days ago
BucketLoot preview

BucketLoot

GitHubredhuntlabs/bucketloot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

cloud-infrastructure-securitycloud-securityinformation-gathering+4
4467 months ago
ConMachi preview

ConMachi

GitHubnccgroup/conmachi

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

cloud-infrastructure-securityconfiguration-auditingcontainer-security+4
1067 years ago
vmsan preview

vmsan

GitHubangelorc/vmsan

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

cloud-infrastructure-securitycontainer-securitydevsecops+3
825 months ago
IMDShift preview

IMDShift

GitHubayushpriya10/imdshift

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
563 years ago
authkeysync preview

authkeysync

GitHubeduardolat/authkeysync

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

authenticationauthentication-authorizationcloud-infrastructure-security+3
288 months ago
Januscape-Hotfix preview

Januscape-Hotfix

GitHubaoripus-ltd/januscape-hotfix

Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel…

cloud-infrastructure-securityconfiguration-auditingincident-response+2
51 month ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
15 days ago
azpim preview

azpim

GitHubtapanmeena/azpim

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

authentication-authorizationcloud-infrastructure-securitycloud-security+3
66 months ago
Dop2Mop preview

Dop2Mop

GitHubh4wkst3r/dop2mop

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML…

cloud-infrastructure-securitycloud-securitycontainer-security+8
44 months ago
S3-from-csp preview

S3-from-csp

GitHubrandomrobbiebf/s3-from-csp

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

cloud-infrastructure-securitycloud-securityinformation-gathering+2
13 years ago
Aurea preview

Aurea

GitLabroxanne_ardary/aurea

Aurea is an open-source, AI-powered platform that secures infrastructure-as-code (IaC) across Terraform, Kubernetes, Docker, and Ansible. It…

ai-securitycloud-infrastructure-securitycontainer-security+5
28 days ago
AutomatedLab preview

AutomatedLab

GitHubautomatedlab/automatedlab

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

cloud-infrastructure-securityeducationlabs-practice+1
2.2k1 month ago
s3-leaks preview

s3-leaks

GitHubnagwww/s3-leaks

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

cloud-infrastructure-securitycloud-securitycurated-resources+2
4576 days ago
repokid preview

repokid

GitHubnetflix/repokid

AWS Least Privilege for Distributed, High-Velocity Deployment

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
1.1k4 years ago
Previous12Next