Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
240 results
vulnhawk preview

vulnhawk

GitHubmomenbasel/vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

ai-securityapi-security-testingcloud-security+8
812 months ago
gh-safe-repo preview

gh-safe-repo

GitHubariesq/gh-safe-repo

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

cloud-securityconfiguration-auditingdevsecops+4
372 days ago
90DaysOfCyberSecurity preview

90DaysOfCyberSecurity

GitHubfarhanashrafdev/90daysofcybersecurity

Structured 90-day cybersecurity study plan with daily tasks covering Network+, Security+, Linux, Python, traffic analysis, cloud security, and…

cloud-securityctfcurated-resources+4
18.6k9 months ago
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k3 days ago
ElectricEye preview

ElectricEye

GitHubjonrau1/electriceye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

cloud-securityconfiguration-auditingdevsecops+5
1.0k11 months ago
PMapper preview

PMapper

GitHubnccgroup/pmapper

A tool for quickly evaluating IAM permissions in AWS.

cloud-securityidentity-access-managementpenetration-testing+2
1.6k4 years ago
dploot preview

dploot

GitHubzblurx/dploot

DPAPI looting remotely and locally in Python

cloud-securitydigital-forensicsencryption-decryption-tools+3
5575 days ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
python-pentesting preview

python-pentesting

GitHubustayready/python-pentesting

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

cloud-securitycommand-and-controleducation+6
2196 years ago
check_mdi preview

check_mdi

GitHubexpl0itabl3/check_mdi

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

cloud-infrastructure-securitycloud-securityinformation-gathering+2
2241 year ago
AutoFunkt preview

AutoFunkt

GitHubredsiege/autofunkt

Python script for automating the creation of serverless cloud redirectors from Cobalt Strike malleable C2 profiles

cloud-securitycommand-and-controlred-teaming
2042 years ago
sandcastle preview

sandcastle

GitHub0xsearches/sandcastle

🏰 A Python script for AWS S3 bucket enumeration.

cloud-securityinformation-gatheringreconnaissance+1
1469 years ago
gh-hijack-runner preview

gh-hijack-runner

GitHubsynacktiv/gh-hijack-runner

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

cloud-securitydata-exfiltrationexploitation+3
331 year ago
PQC-Scanner preview

PQC-Scanner

GitHubcyberjez/pqc-scanner

The PQC Network Scanner is a quantum‑focused network assessment tool that scans TLS/SSL certificates across enterprise environments to identify…

cloud-securitycryptographynetwork-security+2
188 months ago
flask_heroku_redirector preview

flask_heroku_redirector

GitHubkillswitch-gui/flask_heroku_redirector

flask heroku C2 redirector template

cloud-securitycommand-and-controlpenetration-testing+3
119 years ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
17 days ago
react2shell-toolkit preview

react2shell-toolkit

GitHubolezhaku/react2shell-toolkit

Toolkit for CVE-2025-55182, also known as React2Shell.

cloud-securitydatabase-securityexploitation+8
42 months ago
CVE-2026-2472-Vertex-AI-SDK-Google-Cloud preview

CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

GitHubmegafart1/cve-2026-2472-vertex-ai-sdk-google-cloud

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

ai-securitycloud-securityeducation+3
28h 46m ago
Previous12…14Next