Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
580 results
CVE-2026-31431 preview

CVE-2026-31431

GitHubslauger/cve-2026-31431

Analysis and mitigation guide for CVE-2026-31431, a Linux kernel local privilege escalation in the crypto algif_aead subsystem, with impact…

cloud-securitycontainer-securityexploitation+2
1
4 months ago
IngressNightmare-RCE-POC preview

IngressNightmare-RCE-POC

GitHub1w4y/ingressnightmare-rce-poc

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

cloud-securitycontainer-securityeducation+5
11 year ago
DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint- preview

DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-

GitHubsastraadiwiguna-purpleeliteteaming/ddos-purple-teaming-offensive-multi-vector-7-tier-defensive-holistic-blueprint-

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

cloud-securitycommand-and-controldefensive-tools+9
8 months ago
chart-down preview

chart-down

GitHubrandomrobbiebf/chart-down

Extracts all the chart lists from ChartMuseum

cloud-securitycontainer-securitydevsecops+2
6 months ago
SpeculativeExecutionAssessment preview

SpeculativeExecutionAssessment

GitHubgregaskew/speculativeexecutionassessment

Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754

cloud-securityconfiguration-auditinghardware-security+3
6 years ago
Serverless-Goat preview

Serverless-Goat

GitHubowasp/serverless-goat

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

cloud-securityeducationlabs-practice+3
3317 years ago
studio preview

studio

GitHubshipsecai/studio

Workflow automation for Security Teams

cloud-securitydevsecopseducation+7
3796 months ago
CVE-2022-41828 preview

CVE-2022-41828

GitHubmurataydemir/cve-2022-41828

[CVE-2022-41828] Amazon AWS Redshift JDBC Driver Remote Code Execution (RCE)

cloud-securitydatabase-securityeducation+3
43 years ago
CVE-2021-38647-POC-and-Demo-environment preview

CVE-2021-38647-POC-and-Demo-environment

GitHubsimenbai/cve-2021-38647-poc-and-demo-environment

OMIGod / CVE-2021-38647 POC and Demo environment

cloud-securityeducationexploitation+3
34 years ago
CVE-2026-65321-pyathena preview

CVE-2026-65321-pyathena

GitHubrahulreddykarne/cve-2026-65321-pyathena

SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)

cloud-securitydatabase-securityeducation+2
1 month ago
POC_CVE-2026-42880 preview

POC_CVE-2026-42880

GitHubhaerin-l/poc_cve-2026-42880

Reproduces CVE-2026-42880, a critical ArgoCD vulnerability exposing Kubernetes Secrets via ServerSideDiff. Includes automated lab setup, trigger…

cloud-securityeducationexploitation+4
3 months ago
CVE-2026-32794 preview

CVE-2026-32794

GitHubsnailsploit/cve-2026-32794

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

cloud-securityeducationmisconfiguration+3
4 months ago
serverless-application-model preview

serverless-application-model

GitHubaws/serverless-application-model

Transforms SAM templates into CloudFormation resources, generating Lambda functions, IAM roles, and policies with built-in serverless best practices.

cloud-infrastructure-securitycloud-securitydevsecops+1
9.6k3 days ago
kubeshark preview

kubeshark

GitHubkubeshark/kubeshark

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

ai-securitycloud-infrastructure-securitycloud-security+9
12.1k6 days ago
cloudquery preview

cloudquery

GitHubcloudquery/cloudquery

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
6.5k7h 8m ago
Claude-BugHunter preview

Claude-BugHunter

GitHubelementalsouls/claude-bughunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

api-securitycloud-securitycurated-resources+8
4.5k1 day ago
cloudmapper preview

cloudmapper

GitHubduo-labs/cloudmapper

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
6.3k2 years ago
kics preview

kics

GitHubcheckmarx/kics

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

cloud-infrastructure-securitycloud-securitycode-analysis+10
2.7k3h 53m ago
Previous1…272829…33Next