Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
89 results
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k
1 day ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k1 day ago
s3dns preview

s3dns

GitHubolizimmermann/s3dns

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

cloud-securitydns-analysisinformation-gathering+5
1281 day ago
cloud preview

cloud

GitHubtrickest/cloud

Daily updated SSL certificate dataset for AWS EC2 and GCP IP ranges, enabling subdomain enumeration, origin IP discovery, and cloud asset…

cloud-securitydns-subdomain-enumerationinformation-gathering+5
946 days ago
cloudlist preview

cloudlist

GitHubprojectdiscovery/cloudlist

Multi-cloud asset enumeration tool that aggregates resources from AWS, GCP, Azure, and 20+ providers with keyless auth, filters, and multiple output…

cloud-securityinformation-gatheringreconnaissance
1.0k14 days ago
AzureHound preview

AzureHound

GitHubspecterops/azurehound

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

cloud-securityinformation-gatheringosint+2
94914 days ago
SubDomainizer preview

SubDomainizer

GitHubnsonaniya2010/subdomainizer

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

cloud-securityinformation-gatheringosint+2
1.9k14 days ago
apimspray preview

apimspray

GitHubcrtvrffnrt/apimspray

Azure APIM-based password spraying toolkit with IP rotation for authorized red team assessments. Supports spray and validate modes with configurable…

cloud-securityinformation-gatheringosint+3
6115 days ago
CloudPrivs preview

CloudPrivs

GitHubabstractclass/cloudprivs

Determine privileges from cloud credentials via brute-force testing.

cloud-securityinformation-gatheringpenetration-testing+2
691 month ago
CredSpy preview

CredSpy

GitHubredbyte1337/credspy

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

authenticationcloud-securityidentity-access-management+5
1651 month ago
S3Scanner preview

S3Scanner

GitHubsa7mon/s3scanner

Scan for misconfigured S3 buckets across S3-compatible APIs!

cloud-securityinformation-gatheringmisconfiguration+1
3.2k1 month ago
PurplePanda preview

PurplePanda

GitHubcarlospolop/purplepanda

Identify privilege escalation paths within and across different clouds

cloud-securityinformation-gatheringpenetration-testing+3
7201 month ago
cloud_enum preview

cloud_enum

GitHubinitstring/cloud_enum

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

cloud-securityinformation-gatheringosint+2
2.1k1 month ago
s3enum preview

s3enum

GitHubkoenrh/s3enum

Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.

cloud-securitydns-analysisinformation-gathering+2
2781 month ago
CVE-2026-55726 preview

CVE-2026-55726

GitHubmichaeladamgroberman/cve-2026-55726

CVE-2026-55726 disclosure detailing a publicly listable Azure Blob Storage container exposing Gardyn IoT device logs, including SSIDs, firmware…

cloud-securityinformation-gatheringiot-security+3
1 month ago
CVE-2026-13768 preview

CVE-2026-13768

GitHubmichaeladamgroberman/cve-2026-13768

CVE-2026-13768 advisory detailing critical Azure IoT Hub iothubowner credential abuse enabling fleet-wide device enumeration, remote code execution…

cloud-securityexploitationiot-security+5
1 month ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

Automated reconnaissance tool that performs subdomain enumeration, vulnerability scanning, OSINT, port scanning, and web analysis to map attack…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.0k1 month ago
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

cloud-securitycurated-resourceseducation+8
352 months ago
Previous12345Next