Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
582 results
ws4-secure-design-agentic-systems preview

ws4-secure-design-agentic-systems

GitHubcosai-oasis/ws4-secure-design-agentic-systems

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

ai-securitycloud-securitycurated-resources+6
131
6h 31m ago
quantum-security-project preview

quantum-security-project

GitHubowasp/quantum-security-project

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

cloud-securitycryptographycurated-resources+8
998 days ago
igvm preview

igvm

GitHubmicrosoft/igvm

Rust library and format specification for creating and loading Independent Guest Virtual Machine (IGVM) files, supporting hardware-isolated VMs with…

cloud-securityembedded-systems-securityfirmware-analysis+2
15512 days ago
litespeed-cpanel-cve-2026-54420-fix preview

litespeed-cpanel-cve-2026-54420-fix

GitHubmahfuzreham/litespeed-cpanel-cve-2026-54420-fix

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

cloud-securityconfiguration-auditingdefensive-tools+7
23 months ago
CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath preview

CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath

GitHubgeorge0papasotiriou/cve-2026-21008-kubernetes-service-account-token-mounted-in-hostpath

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

cloud-infrastructure-securitycloud-securitycontainer-security+4
1 month ago
litespeed-cpanel-cve-2026-54420-fix preview

litespeed-cpanel-cve-2026-54420-fix

GitHubresellnom/litespeed-cpanel-cve-2026-54420-fix

Defensive mitigation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel plugin, providing symlink detection, IOC hunting, and remediation…

cloud-securityconfiguration-auditingdefensive-tools+6
3 months ago
kali-linux-docker preview

kali-linux-docker

GitHubnu11secur1ty/kali-linux-docker

kali-linux-docker

cloud-securitycontainer-securitydevsecops+8
16 years ago
ADC-19781 preview
Archived

ADC-19781

GitHubj81blog/adc-19781

Check ADC for CVE-2019-19781

cloud-securityconfiguration-auditingincident-response+3
36 years ago
s3reverse preview

s3reverse

GitHubhahwul/s3reverse

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

cloud-securityinformation-gatheringmisconfiguration+1
913 years ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
18 days ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubrocket-panda/cve-2025-9074

Bash-based exploit script for CVE-2025-9074 that abuses the internal Docker API to mount the host C drive, execute commands inside a container, and…

cloud-securitycontainer-escapeexploitation+3
5 months ago
POC_CVE-2025-29943_Write-what-where-Condition preview

POC_CVE-2025-29943_Write-what-where-Condition

GitHubfevar54/poc_cve-2025-29943_write-what-where-condition

Proof-of-concept for CVE-2025-29943 exploiting an undocumented stack engine bit in AMD Zen CPUs to corrupt the stack pointer in SEV-SNP protected…

binary-exploitationcloud-securityexploitation+3
7 months ago
CVE-2021-43858-MinIO preview

CVE-2021-43858-MinIO

GitHubkhuntor/cve-2021-43858-minio

Go-based exploit for CVE-2021-43858 targeting MinIO privilege escalation vulnerability. Executes against a specified IP and port to demonstrate the…

cloud-securityexploitationpenetration-testing+3
3 years ago
CyberStrikeAI preview

CyberStrikeAI

GitHubed1s0nz/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+9
6.8k1 day ago
CyberStrikeAI preview

CyberStrikeAI

GitHubaipentest/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+8
6.6k1 day ago
pacu preview

pacu

GitHubrhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

cloud-infrastructure-securitycloud-securitydata-exfiltration+7
5.3k5 months ago
hacker-container preview

hacker-container

GitHubmadhuakula/hacker-container

The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers,…

cloud-securitycontainer-securitypenetration-testing+1
2953 years ago
IngressNightmare-PoC preview

IngressNightmare-PoC

GitHubhakaioffsec/ingressnightmare-poc

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

cloud-securitycontainer-securityeducation+5
2501 year ago
Previous1…131415…33Next