Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
983 results
CVE-2022-22948 preview

CVE-2022-22948

GitHubpenteraio/cve-2022-22948

Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter

cloud-securityconfiguration-auditingexploitation+3
11
3 years ago
whalescan preview

whalescan

GitHubsaira-h/whalescan

Vulnerability scanner for Windows containers

cloud-securitycontainer-securitymisconfiguration+1
76 years ago
vScalation-CVE-2021-22015 preview

vScalation-CVE-2021-22015

GitHubpenteraio/vscalation-cve-2021-22015

Scanner for vScalation (CVE-2021-22015) a Local Privilege Escalation in VMWare vCenter

cloud-securityexploitationpenetration-testing+3
63 years ago
r2s preview

r2s

GitHubmxm0z/r2s

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

api-security-testingcloud-securityexploitation+3
9 months ago
cve-2025-24514 preview

cve-2025-24514

GitHubkimjuhyeong95/cve-2025-24514

Remote vulnerability scanner for CVE-2025-24514, an ingress-nginx auth-url injection leading to NGINX config manipulation and potential RCE.…

cloud-securitycontainer-securityexploitation+3
1 year ago
pulsar preview
Archived

pulsar

GitHub0x0fb0/pulsar

Network footprint scanner platform. Discover domains and run your custom checks periodically.

cloud-securitydns-subdomain-enumerationinformation-gathering+6
4304 years ago
kube-trivy preview

kube-trivy

GitHubmasahiro331/kube-trivy

Trivy for Kubernetes

cloud-securitycontainer-securityvulnerability-scanners
47 years ago
s3crets_scanner preview

s3crets_scanner

GitHubeilonh/s3crets_scanner

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

cloud-infrastructure-securitycloud-securitysecret-detection+1
5733 years ago
cred_scanner preview

cred_scanner

GitHubdisruptops/cred_scanner

A simple file-based scanner to look for potential AWS access and secret keys in files

cloud-securitycode-analysisdevsecops+1
948 years ago
nextssrf preview

nextssrf

GitHubynsmroztas/nextssrf

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

cloud-securityexploitationinformation-gathering+3
774 months ago
rusty-hog preview

rusty-hog

GitHubnewrelic/rusty-hog

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

cloud-securitycode-analysisdevsecops+1
5591 month ago
BlobHunter preview

BlobHunter

GitHubcyberark/blobhunter

Find exposed data in Azure with this public blob scanner

cloud-infrastructure-securitycloud-securityinformation-gathering+2
3612 years ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.3k2 days ago
agent-bom preview

agent-bom

GitHubmsaad00/agent-bom

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

ai-securitycloud-securitycontainer-security+6
311 day ago
sss3 preview

sss3

GitHubhalencarjunior/sss3

Automated S3 bucket security scanner that tests domain lists for publicly accessible buckets with listing permissions, exporting results for cloud…

cloud-securityinformation-gatheringpenetration-testing+1
324 years ago
mongobleed-exploit-CVE-2025-14847 preview

mongobleed-exploit-CVE-2025-14847

GitHubfranksec42/mongobleed-exploit-cve-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

cloud-securitycontainer-securitydatabase-security+6
36 months ago
CVE-2024-41110-SCAN preview

CVE-2024-41110-SCAN

GitHubpauloparopp/cve-2024-41110-scan

Python-based scanner that checks Docker hosts for CVE-2024-41110 by detecting vulnerable Docker versions and AuthZ plugin usage.

cloud-securitycontainer-securityexploitation+3
2 years ago
festin preview

festin

GitHubcr0hn/festin

FestIn - Open S3 Bucket Scanner

cloud-securitycrawlerdns-analysis+3
2339 days ago
Previous123…55Next