Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1308 results
kata-containers preview

kata-containers

GitHubkata-containers/kata-containers

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

cloud-infrastructure-securitycloud-securitycontainer-escape+4
8.8k
10h 34m ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

authenticationcloud-securitydevsecops+3
5036 months ago
f8x preview

f8x

GitHubffffffff0x/f8x

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

cloud-securityctfdevsecops+7
2.2k1 month ago
aws-security-assessment-solution preview

aws-security-assessment-solution

GitHubawslabs/aws-security-assessment-solution

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
62810 days ago
365Inspect preview

365Inspect

GitHubsoteria-security/365inspect

A PowerShell script that automates the security assessment of Microsoft 365 environments.

cloud-securityconfiguration-auditingdefensive-tools+2
6611 year ago
IngressNightmare-PoC preview

IngressNightmare-PoC

GitHubhakaioffsec/ingressnightmare-poc

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

cloud-securitycontainer-securityeducation+5
2491 year ago
go-pillage-registries preview

go-pillage-registries

GitHubnccgroup/go-pillage-registries

Pentester-focused Docker registry tool to enumerate and pull images

cloud-securitycontainer-securityinformation-gathering+3
1136 years ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubzenzue/cve-2025-9074

Proof-of-concept exploit for CVE-2025-9074 demonstrating container-to-host file write via exposed Docker Engine API on Windows. For authorized…

cloud-securitycontainer-escapecontainer-security+6
101 year ago
secure-by-default-rce-demo preview

secure-by-default-rce-demo

GitHubmeganekos/secure-by-default-rce-demo

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

cloud-securitycontainer-securitydevsecops+6
8 months ago
PowerZure preview

PowerZure

GitHubhausec/powerzure

PowerShell framework to assess Azure security

cloud-securityexploitationpenetration-testing+1
1.3k11 months ago
DVFaaS-Damn-Vulnerable-Functions-as-a-Service preview

DVFaaS-Damn-Vulnerable-Functions-as-a-Service

GitHubwe45/dvfaas-damn-vulnerable-functions-as-a-service

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

cloud-securityeducationlabs-practice+1
1373 years ago
litebox preview

litebox

GitHubmicrosoft/litebox

A security-focused library OS supporting kernel- and user-mode execution

cloud-securitycontainer-securityembedded-systems-security+1
2.7k3 days ago
igvm preview

igvm

GitHubmicrosoft/igvm

Rust library and format specification for creating and loading Independent Guest Virtual Machine (IGVM) files, supporting hardware-isolated VMs with…

cloud-securityembedded-systems-securityfirmware-analysis+2
15518 days ago
BlueTeam.Lab preview

BlueTeam.Lab

GitHubop7ic/blueteam.lab

Blue Team detection lab created with Terraform and Ansible in Azure.

cloud-securityconfiguration-auditingdefensive-tools+7
1911 year ago
jailer preview

jailer

GitHubgen0sec/jailer

Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task_storage…

cloud-securitycontainer-securitydefensive-tools+1
592 days ago
private-landing preview

private-landing

GitHubvhscom/private-landing

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

api-securityauthenticationauthentication-authorization+8
794 months ago
CVE-2022-29170 preview

CVE-2022-29170

GitHubyijikeji/cve-2022-29170

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to…

cloud-securityexploitationmisconfiguration+2
3 years ago
cryptomator preview

cryptomator

GitHubcryptomator/cryptomator

Cross-platform client-side encryption for cloud storage with AES-256, encrypted filenames, obfuscated folder structure, and transparent virtual drive…

cloud-securitycryptographyencryption-decryption-tools+1
16.2k5 days ago
Previous12…73Next