Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
166 results
firezone preview

firezone

GitHubfirezone/firezone

WireGuard-based zero-trust access platform providing secure, peer-to-peer remote access with granular policy controls, SSO authentication, and audit…

authentication-authorizationcloud-securitydevsecops+1
9.1k
1h 7m ago
CloudBrute preview

CloudBrute

GitHub0xsha/cloudbrute

Uncover a target's cloud infrastructure, files, and apps across major providers (AWS, Azure, GCP) using unauthenticated enumeration with concurrent…

cloud-securityinformation-gatheringosint+2
1.1k1 year ago
parsec-cloud preview

parsec-cloud

GitHubscille/parsec-cloud

Open source Dropbox-like file sharing with full client encryption !

authentication-authorizationcloud-securityencryption-decryption-tools+1
30912h 2m ago
CloudGrappler preview

CloudGrappler

GitHubpermiso-io-tools/cloudgrappler

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

cloud-securitydefensive-toolsincident-response+2
2679 months ago
Cloudtopolis preview

Cloudtopolis

GitHubjoelgmsec/cloudtopolis

Zero Infrastructure Password Cracking

cloud-securityeducationpassword-cracking+1
4172 years ago
kontext-cli preview

kontext-cli

GitHubkontext-security/kontext-cli

Secure agents in seconds with permissions enforced at runtime.

ai-securityauthentication-authorizationcloud-security+3
22010h 40m ago
leakdb preview

leakdb

GitHubmoloch--/leakdb

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

cloud-securitydata-exfiltrationinformation-gathering+2
1916 years ago
AzTokenFinder preview

AzTokenFinder

GitHubhackmichnet/aztokenfinder

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

authenticationcloud-securitymemory-forensics+3
1093 years ago
AWS-Key-Hunter preview

AWS-Key-Hunter

GitHubiamlucif3r/aws-key-hunter

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

cloud-securitycode-analysisinformation-gathering+2
401 year ago
scopeblind-gateway preview

scopeblind-gateway

GitHubscopeblind/scopeblind-gateway

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

ai-securityauthentication-authorizationcloud-security+5
915h 21m ago
The Vault by Focused Hunts preview

The Vault by Focused Hunts

GitLabfocused.hunts/the.vault

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

authentication-authorizationcloud-securityencryption-decryption-tools+3
15 days ago
CVE-2021-21975 preview

CVE-2021-21975

GitHubmurataydemir/cve-2021-21975

[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)

cloud-securityexploitationinformation-gathering+3
45 years ago
Prommetrix preview

Prommetrix

GitHubepsylon/prommetrix

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

cloud-securityinformation-gatheringmisconfiguration+4
52 years ago
aisecplus-week01-servicenow-ai-security-incident preview

aisecplus-week01-servicenow-ai-security-incident

GitHubololadeabiola03/aisecplus-week01-servicenow-ai-security-incident

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

ai-securityauthentication-authorizationcloud-security+5
3 months ago
CVE-2021-41805 preview

CVE-2021-41805

GitHubacfirthh/cve-2021-41805

A proof-of-concept for CVE-2021-41805 which is a vulnerability in HashiCorp Consul Enterprise allowing for Remote Code Execution (RCE) with escalated…

cloud-securityeducationexploitation+4
1 year ago
ironclaw preview

ironclaw

GitHubnearai/ironclaw

Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

ai-securityauthentication-authorizationcloud-security+6
12.6k4 days ago
resiprocate preview

resiprocate

GitHubresiprocate/resiprocate

C++ implementation of SIP, ICE, TURN and related protocols.

cloud-securityencryption-decryption-toolsiot-security+3
7942 days ago
CVE-2021-38647 preview

CVE-2021-38647

GitHubhorizon3ai/cve-2021-38647

Proof-of-concept exploit for CVE-2021-38647 (OMIGOD), an unauthenticated remote code execution vulnerability in the OMI agent commonly deployed on…

cloud-securityexploitationpenetration-testing+3
2334 years ago
Previous1…8910Next