Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
131 results
CloudHunter preview

CloudHunter

GitHub1n3/cloudhunter

Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them

cloud-securitydns-analysisinformation-gathering+2
35
8 years ago
POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability preview

POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability

GitHubsam00/poc-cve-2026-42826-2026-42826-microsoft-azure-devops-information-disclosure-vulnerability

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

cloud-securityexploitationinformation-gathering+4
1 month ago
secret-regex-list preview

secret-regex-list

GitHubh33tlit/secret-regex-list

List of regex for scraping secret API keys and juicy information.

api-securitycloud-securityinformation-gathering+3
7324 years ago
SnaffPoint preview

SnaffPoint

GitHubnheiniger/snaffpoint

A tool for pointesters to find candies in SharePoint

cloud-securityinformation-gatheringpenetration-testing+3
2893 years ago
TokenMan preview

TokenMan

GitHubsecureworks/tokenman

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

authenticationcloud-securityinformation-gathering+2
1033 years ago
azbelt preview

azbelt

GitHubdaddycocoaman/azbelt

AAD related enumeration in Nim

authenticationcloud-securityidentity-access-management+5
1323 years ago
untitledgoosetool preview

untitledgoosetool

GitHubcisagov/untitledgoosetool

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

cloud-securitydefensive-toolsdigital-forensics+4
9657 months ago
CVE-2026-67620-poc preview

CVE-2026-67620-poc

GitHubabdugafforov-bobur/cve-2026-67620-poc

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

cloud-securityexploitationinformation-gathering+4
11 month ago
Gemini-api-key-hunter preview

Gemini-api-key-hunter

GitHubcoffinxp/gemini-api-key-hunter

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

api-securitycloud-securityinformation-gathering+5
712 months ago
Maestro preview

Maestro

GitHubmayyhem/maestro

Abusing Azure services over C2

authenticationcloud-securitycommand-and-control+4
3827 months ago
onedrive_user_enum preview

onedrive_user_enum

GitHubnyxgeek/onedrive_user_enum

onedrive user enumeration - pentest tool to enumerate valid o365 users

cloud-securityinformation-gatheringosint+3
7691 year ago
AWS-Key-Hunter preview

AWS-Key-Hunter

GitHubiamlucif3r/aws-key-hunter

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

cloud-securitycode-analysisinformation-gathering+2
401 year ago
grafana-ssrf preview

grafana-ssrf

GitHubrandomrobbiebf/grafana-ssrf

Authenticated SSRF in Grafana

cloud-securityexploitationinformation-gathering+4
832 years ago
Prommetrix preview

Prommetrix

GitHubepsylon/prommetrix

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

cloud-securityinformation-gatheringmisconfiguration+4
52 years ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Appspec YML and YAML leaks

api-securitycloud-securityinformation-gathering+4
12 years ago
Azure-APIM-Cross-Tenant-Signup-Bypass preview

Azure-APIM-Cross-Tenant-Signup-Bypass

GitHubbountyyfi/azure-apim-cross-tenant-signup-bypass

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

api-securitycloud-securityinformation-gathering+4
162 months ago
CVE-2023-28432 preview

CVE-2023-28432

GitHubmzzdtot/cve-2023-28432

MinIO敏感信息泄露漏洞批量扫描poc&exp

cloud-securityexploitationinformation-gathering+3
373 years ago
Previous12…8Next