Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
ZeusCloud preview

ZeusCloud

GitHubzeus-labs/zeuscloud

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
734
3 years ago
ccat preview

ccat

GitHubrhinosecuritylabs/ccat

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

cloud-securitycontainer-securityexploitation+1
6536 years ago
CloudBrute preview

CloudBrute

GitHub0xsha/cloudbrute

Uncover a target's cloud infrastructure, files, and apps across major providers (AWS, Azure, GCP) using unauthenticated enumeration with concurrent…

cloud-securityinformation-gatheringosint+2
1.1k1 year ago
awspx preview

awspx

GitHubreverseclabs/awspx

A graph-based tool for visualizing effective access and resource relationships in AWS environments.

cloud-infrastructure-securitycloud-securityinformation-gathering+3
1.0k5 years ago
apex preview

apex

GitHubpensarai/apex

AI-powered offensive security testing using autonomous agents, directly in your terminal.

ai-securitycloud-securitydevsecops+7
3143 days ago
Nebula preview

Nebula

GitHubgl4ssesbo1/nebula

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to…

cloud-securitycommand-and-controlexploit-frameworks+3
6351 year ago
hacker-container preview

hacker-container

GitHubmadhuakula/hacker-container

The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers,…

cloud-securitycontainer-securitypenetration-testing+1
2973 years ago
Aaia preview

Aaia

GitHubrams3sh/aaia

AWS Identity and Access Management Visualizer and Anomaly Finder

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
2972 years ago
GoMapEnum preview

GoMapEnum

GitHubnodauf/gomapenum

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

cloud-securityemail-harvestinginformation-gathering+4
4931 year ago
python-pentesting preview

python-pentesting

GitHubustayready/python-pentesting

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

cloud-securitycommand-and-controleducation+6
2196 years ago
cloud preview

cloud

GitHubtrickest/cloud

Monitoring the Cloud Landscape

cloud-securitydns-subdomain-enumerationinformation-gathering+5
943 days ago
s3dns preview

s3dns

GitHubolizimmermann/s3dns

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

cloud-securitydns-analysisinformation-gathering+5
1296 days ago
BlueCloud preview

BlueCloud

GitHubiknowjason/bluecloud

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

cloud-infrastructure-securitycloud-securitydefensive-tools+7
1514 years ago
spaces-finder preview

spaces-finder

GitHubappsecco/spaces-finder

A tool to hunt for publicly accessible DigitalOcean Spaces

cloud-infrastructure-securitycloud-securityinformation-gathering+4
1566 years ago
AzureAttackKit preview

AzureAttackKit

GitHubzephrfish/azureattackkit

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

cloud-securitycurated-resourcesexploitation+6
792 months ago
edge preview

edge

GitHubiknowjason/edge

Whois for the Cloud: Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.

cloud-securitydns-analysisinformation-gathering+4
18711 months ago
AWS-Loot preview

AWS-Loot

GitHubsebastian-mora/aws-loot

Enumerates AWS environments for secrets by scanning EC2 userdata, Lambda environment variables and source code, and CodeBuild instances for…

cloud-securityinformation-gatheringpenetration-testing+1
656 years ago
Cybersecurity-Handbook preview

Cybersecurity-Handbook

GitHubpriyanshu-rawa/cybersecurity-handbook

Open-source cybersecurity knowledge base with 400+ notes, labs, and cheat sheets covering offense, defense, cryptography, cloud, and forensics.

cloud-securitycryptographycurated-resources+7
665 days ago
Previous123Next