Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
honeyLambda preview

honeyLambda

GitHub0x4d31/honeylambda

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

cloud-securitydefensive-toolsincident-response+2
525
7 years ago
365-Stealer preview

365-Stealer

GitHubalteredsecurity/365-stealer

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

cloud-securitypenetration-testingphishing+1
5876 months ago
teller preview

teller

GitHubtellerops/teller

Cloud native secrets management for developers - never leave your command line for secrets.

cloud-infrastructure-securitycloud-securitycode-analysis+2
3.2k8 months ago
PurpleKeep preview

PurpleKeep

GitHubretrospected/purplekeep

Providing Azure pipelines to create an infrastructure and run Atomic tests.

cloud-securityeducationincident-response+4
533 years ago
CVE-2022-3294 preview

CVE-2022-3294

GitHubarbaaz29/cve-2022-3294

Privilege Escalation using nodes/proxy (create action allowed) and nodes/status (update/patch actions allowed)

cloud-securitycontainer-securityexploitation+3
8 months ago
BlueTeam.Lab preview

BlueTeam.Lab

GitHubop7ic/blueteam.lab

Blue Team detection lab created with Terraform and Ansible in Azure.

cloud-securityconfiguration-auditingdefensive-tools+7
1911 year ago
gh-hijack-runner preview

gh-hijack-runner

GitHubsynacktiv/gh-hijack-runner

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

cloud-securitydata-exfiltrationexploitation+3
331 year ago
CloudUnflare preview

CloudUnflare

GitHubgreycatz/cloudunflare

Reconnaissance Real IP address for Cloudflare Bypass

cloud-securitydns-analysisinformation-gathering+2
3706 years ago
gh-safe-repo preview

gh-safe-repo

GitHubariesq/gh-safe-repo

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

cloud-securityconfiguration-auditingdevsecops+4
373 days ago
attack_range preview

attack_range

GitHubsplunk/attack_range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

cloud-securityeducationlabs-practice+1
2.6k1 month ago
aws-security-assessment-solution preview

aws-security-assessment-solution

GitHubawslabs/aws-security-assessment-solution

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
6281 day ago
CVE-2022-27518_POC preview

CVE-2022-27518_POC

GitHubdolby360/cve-2022-27518_poc

Proof-of-concept exploit for CVE-2022-27518 targeting Citrix ADC and Citrix CPX containers, demonstrating remote code execution via crafted HTTP…

cloud-securitycontainer-securityexploitation+2
23 years ago
autovpn preview

autovpn

GitHubttlequals0/autovpn

Create On Demand Disposable OpenVPN Endpoints on AWS.

cloud-securitygeneral-purpose-utilitiesprivacy
2.0k6 months ago
badPods preview

badPods

GitHubbishopfox/badpods

A collection of manifests that will create pods with elevated privileges.

cloud-securitycontainer-escapecontainer-security+4
7119 months ago
iam-vulnerable preview

iam-vulnerable

GitHubbishopfox/iam-vulnerable

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

cloud-securityeducationidentity-access-management+4
5901 year ago
cloudfoxable preview

cloudfoxable

GitHubbishopfox/cloudfoxable

Create your own vulnerable by design AWS penetration testing playground

cloud-infrastructure-securitycloud-securityctf+3
4754 months ago
tunnelx preview

tunnelx

GitHubprojectdiscovery/tunnelx

TunnelX is a lightweight ingress tunneling tool designed to create a secure SOCKS5 proxy server for routing network traffic.

authenticationcloud-securitynetwork-security+3
31 month ago
CVE-2025-62506 preview

CVE-2025-62506

GitHubyoshino-s/cve-2025-62506

Verification script for CVE-2025-62506, a privilege escalation vulnerability in MinIO service accounts, testing if restricted accounts can bypass…

cloud-securityexploitationpenetration-testing+2
11 months ago
Previous12Next