Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
CVE-2025-34159 preview

CVE-2025-34159

GitHubeyodav/cve-2025-34159

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

cloud-securitycontainer-securityexploitation+5
1 year ago
globalping-probe preview

globalping-probe

GitHubjsdelivr/globalping-probe

The globalping probe code that runs on your hardware and connects to the global community network of probes

cloud-securitydevsecopsdns-analysis+3
2122 days ago
kube-knark preview

kube-knark

GitHubchen-keinan/kube-knark

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

cloud-securitycontainer-securityintrusion-detection+1
364 years ago
WhatTheHack preview

WhatTheHack

GitHubmicrosoft/whatthehack

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

ai-securitycloud-infrastructure-securitycloud-security+6
1.9k3 months ago
Copy-Fail-CVE-2026-31431-Kubernetes-PoC preview

Copy-Fail-CVE-2026-31431-Kubernetes-PoC

GitHubpercivalll/copy-fail-cve-2026-31431-kubernetes-poc

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

cloud-securitycontainer-escapeeducation+4
1915 months ago
CVE-2026-53359 preview

CVE-2026-53359

GitHubndouglas-cloudsmith/cve-2026-53359

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

cloud-securitycontainer-escapeexploitation+1
2 months ago
Zapscape preview

Zapscape

GitHubv4bel/zapscape

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

binary-exploitationcloud-securityexploitation+3
1661 month ago
Dirty-Frag-Kubernetes-PoC preview

Dirty-Frag-Kubernetes-PoC

GitHubpercivalll/dirty-frag-kubernetes-poc

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

cloud-securitycontainer-escapeexploitation+3
164 months ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

Access control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run,…

ai-securitycloud-securitycommand-and-control+7
2173 days ago
WIn-CVE-2021-31166 preview

WIn-CVE-2021-31166

GitHubbgsilvait/win-cve-2021-31166

Proof-of-concept for CVE-2021-31166 (http.sys RCE) with Terraform deployment on AWS, including testing scripts and a WAFv2 rule to block the exploit.

cloud-securitydevsecopsexploitation+3
5 years ago
tarian preview

tarian

GitHubdevopstoday11/tarian

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

cloud-securitycontainer-securitydevsecops+2
25 years ago
CVE-2021-38647 preview

CVE-2021-38647

GitHubhorizon3ai/cve-2021-38647

Proof-of-concept exploit for CVE-2021-38647 (OMIGOD), an unauthenticated remote code execution vulnerability in the OMI agent commonly deployed on…

cloud-securityexploitationpenetration-testing+3
2335 years ago
CVE-2022-27251 preview

CVE-2022-27251

GitHubthecybergeek/cve-2022-27251

Remote Code Execution in LocalStack 0.12.6

cloud-securitycontainer-securityeducation+3
4 years ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.4k17h 1m ago
rusty-hog preview

rusty-hog

GitHubnewrelic/rusty-hog

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

cloud-securitycode-analysisdevsecops+1
5582 months ago
AWS-Key-Hunter preview

AWS-Key-Hunter

GitHubiamlucif3r/aws-key-hunter

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

cloud-securitycode-analysisinformation-gathering+2
401 year ago
keyhog preview

keyhog

GitHubsanthreal/keyhog

Open-source secret scanner in Rust

cloud-securitycode-analysisconfiguration-auditing+8
1085 days ago
cnspec preview

cnspec

GitHubmondoohq/cnspec

An open source, cloud-native security to protect everything from build to runtime

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
4412 days ago
Previous12…13Next