Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
cve-2021-43858 preview

cve-2021-43858

GitHub0rx1/cve-2021-43858

Exploit for MinIO privilege escalation vulnerability CVE-2021-43858, allowing unauthorized access to cloud storage. Written in Go, run with 'go run…

cloud-securityexploitationpenetration-testing+2
3
4 years ago
gobuster preview

gobuster

GitHuboj/gobuster

Directory/File, DNS and VHost busting tool written in Go

cloud-securitydns-subdomain-enumerationfuzzing+3
14.2k8 months ago
oathkeeper preview

oathkeeper

GitHubory/oathkeeper

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

api-securityauthenticationauthentication-authorization+5
3.6k2 months ago
ayaFlow preview

ayaFlow

GitHubdavidhavoc/ayaflow

A high-performance, eBPF-based network traffic analyzer written in Rust.

cloud-securitydns-analysisnetwork-mapping+2
2862 months ago
cirrusgo preview

cirrusgo

GitHubph33rr/cirrusgo

A fast tool to scan SAAS,PAAS App written in Go

cloud-securityinformation-gatheringvulnerability-scanners+1
864 years ago
Minio-CVE-2023-28432 preview

Minio-CVE-2023-28432

GitHublhxhl/minio-cve-2023-28432

Detects and exploits MinIO information disclosure vulnerability (CVE-2023-28432) with single and batch URL scanning, written in Go.

cloud-securityexploitationinformation-gathering+3
13 years ago
Metasploit-Module-TFM preview

Metasploit-Module-TFM

GitHubcgv-dev/metasploit-module-tfm

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

cloud-securitycontainer-securityeducation+7
2 years ago
rusty-hog preview

rusty-hog

GitHubnewrelic/rusty-hog

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

cloud-securitycode-analysisdevsecops+1
5582 months ago
spaces-finder preview

spaces-finder

GitHubappsecco/spaces-finder

A tool to hunt for publicly accessible DigitalOcean Spaces

cloud-infrastructure-securitycloud-securityinformation-gathering+4
1566 years ago
scour preview

scour

GitHubgrines/scour

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

cloud-securityexploitationlateral-movement+4
1272 years ago
faraday_agent_dispatcher preview

faraday_agent_dispatcher

GitHubinfobyte/faraday_agent_dispatcher

Faraday Agent Dispatcher launches any security tools and send results to Faradaysec Platform.

cloud-securitydevsecopsinformation-gathering+5
498 months ago
apm preview

apm

GitHubaaravmaloo/apm

A local password manager for everyone

authenticationcloud-securitycryptography+7
304 days ago
aws-recon preview
Archived

aws-recon

GitHubjoshlarsen/aws-recon

Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
5551 year ago
dploot preview

dploot

GitHubzblurx/dploot

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

cloud-securitydigital-forensicsencryption-decryption-tools+3
57518 days ago
offensive-azure preview

offensive-azure

GitHubblacklanternsecurity/offensive-azure

Collection of offensive tools targeting Microsoft Azure

cloud-securityinformation-gatheringpassword-attacks+4
2276 months ago
Honeypot_Smart_Infrastructure preview

Honeypot_Smart_Infrastructure

GitHubadarkst/honeypot_smart_infrastructure

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

cloud-securitycontainer-securityeducation+4
12 years ago
aws_pwn preview

aws_pwn

GitHubdagrz/aws_pwn

A collection of AWS penetration testing junk

cloud-infrastructure-securitycloud-securitydata-exfiltration+6
1.2k8 years ago