Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
cred_scanner preview

cred_scanner

GitHubdisruptops/cred_scanner

A simple file-based scanner to look for potential AWS access and secret keys in files

cloud-securitycode-analysisdevsecops+1
948 years ago
matchlock preview

matchlock

GitHubjingkaihe/matchlock

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

ai-securityapi-securitycloud-security+5
6212 months ago
Metasploit-Module-TFM preview

Metasploit-Module-TFM

GitHubcgv-dev/metasploit-module-tfm

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

cloud-securitycontainer-securityeducation+7
2 years ago
k8scout preview

k8scout

GitHubk8scout/k8scout

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

cloud-securitycontainer-securityinformation-gathering+8
2542 months ago
nhi-zero-trust-bypass preview

nhi-zero-trust-bypass

GitHubalexsvobo/nhi-zero-trust-bypass

Demonstrates a real-world zero-trust bypass by exploiting BIND CVE-2025-40775 to disrupt DNS, break secret rotation, and expose static credentials in…

cloud-securitydns-analysiseducation+5
51 year ago
gh-safe-repo preview

gh-safe-repo

GitHubariesq/gh-safe-repo

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

cloud-securityconfiguration-auditingdevsecops+4
371 day ago
rusty-hog preview

rusty-hog

GitHubnewrelic/rusty-hog

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

cloud-securitycode-analysisdevsecops+1
5591 month ago
trivy-operator preview

trivy-operator

GitHubaquasecurity/trivy-operator

Kubernetes-native security operator that automates vulnerability scanning, configuration auditing, secret detection, RBAC analysis, and compliance…

cloud-securitycontainer-securitymisconfiguration+1
1.9k2 days ago
secret-regex-list preview

secret-regex-list

GitHubh33tlit/secret-regex-list

List of regex for scraping secret API keys and juicy information.

api-securitycloud-securityinformation-gathering+3
7324 years ago
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
28.0k11h 12m ago
TriSuElla-AIDLCA-Framework preview

TriSuElla-AIDLCA-Framework

GitHubowasp/trisuella-aidlca-framework

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

ai-securitycloud-securitycode-analysis+7
210 days ago
git-alerts preview

git-alerts

GitHubboringtools/git-alerts

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

cloud-securitydevsecopssecret-detection+2
2331 month ago
layerleak preview

layerleak

GitHubbrumbelow/layerleak

layerleak the Docker Hub Secret Scanner

api-securitycloud-securitycontainer-security+3
4415 days ago
BucketLoot preview

BucketLoot

GitHubredhuntlabs/bucketloot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

cloud-infrastructure-securitycloud-securityinformation-gathering+4
4448 months ago
keyhog preview

keyhog

GitHubsanthreal/keyhog

Open-source secret scanner in Rust

cloud-securitycode-analysisconfiguration-auditing+8
1054 days ago
envsec preview

envsec

GitHubdavidnussio/envsec

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

authentication-authorizationcloud-securitydevsecops+3
1625 days ago
enseal preview

enseal

GitHubfleralex/enseal

Secure, ephemeral secret sharing for developers.

authenticationcloud-securityconfiguration-auditing+6
56 months ago
vault-conductor preview

vault-conductor

GitHubpirafrank/vault-conductor

An SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager

authenticationcloud-securitydevsecops+3
391 month ago
Previous12Next