Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
885 results
s3crets_scanner preview

s3crets_scanner

GitHubeilonh/s3crets_scanner

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

cloud-infrastructure-securitycloud-securitysecret-detection+1
572
3 years ago
ODIN preview

ODIN

GitHubchrismaddalena/odin

Automated network asset, email, and social media profile discovery and cataloguing.

cloud-securityemail-harvestinginformation-gathering+4
6667 years ago
vuln-list-update preview

vuln-list-update

GitHubaquasecurity/vuln-list-update

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

cloud-securitydevsecopsioc-management+2
1971 day ago
phishlulz preview

phishlulz

GitHubantisnatchor/phishlulz

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

cloud-securitydata-exfiltrationinformation-gathering+4
3379 years ago
BucketLoot preview

BucketLoot

GitHubredhuntlabs/bucketloot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

cloud-infrastructure-securitycloud-securityinformation-gathering+4
4468 months ago
M365-Assess preview

M365-Assess

GitHubgalvnyz/m365-assess

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

cloud-securityconfiguration-auditingdevsecops+4
1971 month ago
brawl-public-game-001 preview

brawl-public-game-001

GitHubmitre/brawl-public-game-001

Data from a BRAWL Automated Adversary Emulation Exercise

adversarial-attackcloud-securitydigital-forensics+7
2148 years ago
metahub preview

metahub

GitHubgabrielsoltz/metahub

Automated security findings enrichment and impact evaluation tool for AWS. Enriches vulnerability data with resource context, associations, and tags…

cloud-securityconfiguration-auditingincident-response+3
1776 months ago
open-sammy preview

open-sammy

GitHubowasp/open-sammy

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

cloud-securityconfiguration-auditingcontainer-security+3
2827 days ago
SyntheticSun preview

SyntheticSun

GitHubjonrau1/syntheticsun

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

anomaly-detectioncloud-securityincident-response+3
825 years ago
Owasp-top-10-k8s-2025 preview

Owasp-top-10-k8s-2025

GitHubhac01/owasp-top-10-k8s-2025

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

cloud-securitycontainer-securityctf+8
481 month ago
kube-alien preview

kube-alien

GitHubnixwizard/kube-alien

Automated Kubernetes cluster penetration testing tool that exploits misconfigurations in API, Kubelet, etcd, and Dashboard to achieve node takeover…

cloud-securitycontainer-securityexploitation+2
255 years ago
POC_CVE-2026-42880 preview

POC_CVE-2026-42880

GitHubhaerin-l/poc_cve-2026-42880

Reproduces CVE-2026-42880, a critical ArgoCD vulnerability exposing Kubernetes Secrets via ServerSideDiff. Includes automated lab setup, trigger…

cloud-securityeducationexploitation+4
3 months ago
domain-protect preview

domain-protect

GitHubovotech/domain-protect

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

cloud-securitymisconfigurationreconnaissance+1
33 years ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
27 months ago
Orchestrated-Powershell-for-CVE-2023-24932 preview

Orchestrated-Powershell-for-CVE-2023-24932

GitHubhelleflo1312/orchestrated-powershell-for-cve-2023-24932

Automated PowerShell orchestrator for applying Secure Boot mitigations against CVE-2023-24932 (BlackLotus). Handles registry changes, reboots,…

cloud-securityconfiguration-auditingincident-response+3
15 months ago
Magnohost-Vulnerabilities-pentest preview

Magnohost-Vulnerabilities-pentest

GitHubwyllowsec/magnohost-vulnerabilities-pentest

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

cloud-securitydatabase-securitydns-analysis+8
13 months ago
d8-copy-fail-mitigation preview

d8-copy-fail-mitigation

GitHubdeckhouse/d8-copy-fail-mitigation

Kubernetes-native CVE-2026-31431 mitigation with automated kernel module blocking, runtime Falco detection rules, and bashible-based node…

cloud-securityconfiguration-auditingcontainer-security+3
3 months ago
Previous123…50Next