Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
terraform-aws-secure-baseline preview

terraform-aws-secure-baseline

GitHubnozaq/terraform-aws-secure-baseline

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
1.2k
4 days ago
ARES preview

ARES

GitHubmafifrizi/ares

Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault,…

cloud-securitycommand-and-controldefensive-tools+5
284 days ago
ssh-tpm-agent preview

ssh-tpm-agent

GitHubfoxboron/ssh-tpm-agent

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

authenticationcloud-securitydevsecops+3
75110 days ago
NGINX_2026_CVE_Bundle_CTI_Report preview

NGINX_2026_CVE_Bundle_CTI_Report

GitHubchpratik/nginx_2026_cve_bundle_cti_report

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

cloud-securitycurated-resourceseducation+6
1 month ago
PurplePanda preview

PurplePanda

GitHubcarlospolop/purplepanda

Identify privilege escalation paths within and across different clouds

cloud-securityinformation-gatheringpenetration-testing+3
7202 months ago
terraform-aws-security-group preview

terraform-aws-security-group

GitLabfer1035_terraform/modules/terraform-aws-security-group

Terraform module to manage AWS Security Groups. Currently, the ingress and egress rules support IPv4, IPv6, and Security Group ID inputs.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
2 months ago
Microsoft-Extractor-Suite preview

Microsoft-Extractor-Suite

GitHubinvictus-ir/microsoft-extractor-suite

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

cloud-securitydigital-forensicsincident-response+3
8472 months ago
NGINX-Rift preview

NGINX-Rift

GitHubnu0l/nginx-rift

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

cloud-securityconfiguration-auditingcontainer-security+3
53 months ago
cve-2026-31431-mitigation preview

cve-2026-31431-mitigation

GitHubyakovyakov/cve-2026-31431-mitigation

Detection and mitigation tooling for CVE-2026-31431 (Copy Fail) on Linux kernels. Includes Phalanx-CCS and Silent4Labs scripts plus an Ansible…

cloud-securityconfiguration-auditingdevsecops+3
4 months ago
d8-copy-fail-mitigation preview

d8-copy-fail-mitigation

GitHubdeckhouse/d8-copy-fail-mitigation

Kubernetes-native CVE-2026-31431 mitigation with automated kernel module blocking, runtime Falco detection rules, and bashible-based node…

cloud-securityconfiguration-auditingcontainer-security+3
4 months ago
All-CEHv13-Module-wise-PDF-Reports preview

All-CEHv13-Module-wise-PDF-Reports

GitHubaniket2912/all-cehv13-module-wise-pdf-reports

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

cloud-securitycryptographyeducation+9
1447 months ago
AADInternals preview

AADInternals

GitHubgerenios/aadinternals

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

authenticationcloud-securityidentity-access-management+2
1.7k11 months ago
DFIR-O365RC preview

DFIR-O365RC

GitHubanssi-fr/dfir-o365rc

PowerShell module for Office 365 and Azure log collection

cloud-securitydigital-forensicsforensics+2
28311 months ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
domain-protect preview
Archived

domain-protect

GitHubdomain-protect/domain-protect

OWASP Domain Protect - prevent subdomain takeover

cloud-securitydevsecopsdns-analysis+4
3941 year ago
Metasploit-Module-TFM preview

Metasploit-Module-TFM

GitHubcgv-dev/metasploit-module-tfm

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

cloud-securitycontainer-securityeducation+7
2 years ago
scour preview

scour

GitHubgrines/scour

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

cloud-securityexploitationlateral-movement+4
1272 years ago
Azure-AD-Incident-Response-PowerShell-Module preview
Archived

Azure-AD-Incident-Response-PowerShell-Module

GitHubazuread/azure-ad-incident-response-powershell-module

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

cloud-infrastructure-securitycloud-securitydefensive-tools+3
4573 years ago
Previous12Next