Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
CorelightForSecOps preview

CorelightForSecOps

GitHubcorelight/corelightforsecops

Chronicle parser for CORELIGHT and related information.

cloud-securitydefensive-toolsintrusion-detection+3
5
3 months ago
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k3 days ago
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k2 months ago
moltis preview

moltis

GitHubmoltis-org/moltis

A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

ai-securityapi-securityauthentication-authorization+7
2.8k10 days ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k2 months ago
metabadger preview
Archived

metabadger

GitHubsalesforce/metabadger

Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
1431 year ago
text4shell-policy preview
Archived

text4shell-policy

GitHubchainguard-dev/text4shell-policy

ClusterImagePolicy demo for cve-2022-42889 text4shell

cloud-securitycontainer-securitydevsecops+3
43 years ago
CVE-2026-21002-Serverless-Cold-Start-Credential-Leakage-via-Reused-tmp preview

CVE-2026-21002-Serverless-Cold-Start-Credential-Leakage-via-Reused-tmp

GitHubgeorge0papasotiriou/cve-2026-21002-serverless-cold-start-credential-leakage-via-reused-tmp

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

cloud-infrastructure-securitycloud-securitydata-exfiltration+4
1 month ago
AI and the Automobile preview

AI and the Automobile

GitLabroxanne_ardary/ai-and-the-automobile

Curated collection of open specifications for AI-integrated vehicle systems, covering autonomy, perception, navigation, energy management, safety,…

cloud-securitycurated-resourceseducation+3
1 month ago
Dirty-Frag-Kubernetes-PoC preview

Dirty-Frag-Kubernetes-PoC

GitHubpercivalll/dirty-frag-kubernetes-poc

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

cloud-securitycontainer-escapeexploitation+3
184 months ago
hawk preview

hawk

GitHubt0pcyber/hawk

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

cloud-infrastructure-securitycloud-securitydigital-forensics+3
9551 year ago
Interview_Tips preview

Interview_Tips

GitHubjigerjain/interview_tips

Summary of Cyber Security interview questions I have been through, hope this helps

binary-exploitationcloud-securitycryptography+5
716 years ago
EU_compliance_MCP preview
Archived

EU_compliance_MCP

GitHubansvar-systems/eu_compliance_mcp

EU focused compliance MCP server

api-securitycloud-securitycurated-resources+5
251 month ago
CVE-2024-10220-Kubernetes-gitRepo-Volume-Vulnerability preview

CVE-2024-10220-Kubernetes-gitRepo-Volume-Vulnerability

GitHubmrk336/cve-2024-10220-kubernetes-gitrepo-volume-vulnerability

CVE-2024-10220 reveals a critical flaw in Kubernetes’ deprecated gitRepo volume type, allowing attackers to execute arbitrary commands via malicious…

cloud-infrastructure-securitycloud-securitycontainer-security+6
1 year ago
bouvet preview

bouvet

GitHubvrn21-arcanist/bouvet

Sandbox for Agents

ai-securitycloud-securitycontainer-security+3
1027 months ago
Azure-Networking-Privilege-Escalation-Exploit-CVE-2025-54914 preview

Azure-Networking-Privilege-Escalation-Exploit-CVE-2025-54914

GitHubmrk336/azure-networking-privilege-escalation-exploit-cve-2025-54914

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

cloud-infrastructure-securitycloud-securityeducation+6
1 year ago
CVE-2026-23007-Serverless-Cold-Start-Memory-Remanence-Data-Leakage- preview

CVE-2026-23007-Serverless-Cold-Start-Memory-Remanence-Data-Leakage-

GitHubgeorge0papasotiriou/cve-2026-23007-serverless-cold-start-memory-remanence-data-leakage-

Simulates CVE-2026-23007 serverless cold-start memory remanence; demonstrates how persistent global state across Lambda invocations can leak secrets…

cloud-securityeducationexploitation+2
1 month ago
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
11 months ago
Previous12Next