Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
81 results
BloodBash preview

BloodBash

GitHubsquidsec/bloodbash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

cloud-securityconfiguration-auditingidentity-access-management+6
492
1 month ago
chithi preview

chithi

GitHubchithi-dev/chithi

The next generation encrypted file sharing project

authentication-authorizationcloud-securitydata-exfiltration+3
1623 months ago
f8x preview

f8x

GitHubffffffff0x/f8x

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

cloud-securityctfdevsecops+7
2.2k2 months ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.3k2 days ago
secureCodeBox preview

secureCodeBox

GitHubsecurecodebox/securecodebox

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

cloud-securitycontainer-securitydevsecops+3
9892 days ago
kata-containers preview

kata-containers

GitHubkata-containers/kata-containers

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

cloud-infrastructure-securitycloud-securitycontainer-escape+4
8.8k1 day ago
nono preview

nono

GitHubnolabs-ai/nono

agent runtime security - zero trust, zero setup, zero latency.

ai-securitycloud-securitycode-analysis+8
4.2k0 days ago
AzureHound preview

AzureHound

GitHubspecterops/azurehound

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

cloud-securityinformation-gatheringosint+2
9614 days ago
CVE-2026-43867 preview

CVE-2026-43867

GitHuboscerd/cve-2026-43867

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

binary-exploitationcloud-securitycode-analysis+2
2 months ago
DVFaaS-Damn-Vulnerable-Functions-as-a-Service preview

DVFaaS-Damn-Vulnerable-Functions-as-a-Service

GitHubwe45/dvfaas-damn-vulnerable-functions-as-a-service

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

cloud-securityeducationlabs-practice+1
1373 years ago
cryptomator preview

cryptomator

GitHubcryptomator/cryptomator

Cross-platform client-side encryption for cloud storage with AES-256, encrypted filenames, obfuscated folder structure, and transparent virtual drive…

cloud-securitycryptographyencryption-decryption-tools+1
16.2k2 days ago
cloud preview

cloud

GitHubtrickest/cloud

Monitoring the Cloud Landscape

cloud-securitydns-subdomain-enumerationinformation-gathering+5
942 days ago
aws-security-assessment-solution preview

aws-security-assessment-solution

GitHubawslabs/aws-security-assessment-solution

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
62822h 14m ago
gha-lab-8aba6b05dc preview

gha-lab-8aba6b05dc

GitHubpvharmo2/gha-lab-8aba6b05dc

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of…

cloud-securitycurated-resourceseducation+3
117 days ago
PingCastleCloud preview
Archived

PingCastleCloud

GitHubnetwrix/pingcastlecloud

Audit program for AzureAD

authentication-authorizationcloud-infrastructure-securitycloud-security+4
1543 years ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

authenticationcloud-securitydevsecops+3
5037 months ago
trident preview
Archived

trident

GitHubpraetorian-inc/trident

automated password spraying tool

authenticationcloud-securitypassword-attacks+3
1485 years ago
quantum-security-project preview

quantum-security-project

GitHubowasp/quantum-security-project

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

cloud-securitycryptographycurated-resources+8
11418 days ago
Previous12345Next