Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
683 results
kubernetes-goat preview

kubernetes-goat

GitHubmadhuakula/kubernetes-goat

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

cloud-securitycontainer-escapecontainer-security+4
5.9k
5 months ago
simulator preview

simulator

GitHubcontrolplaneio/simulator

Kubernetes Security Training Platform - focusing on security mitigation

cloud-securitycontainer-securityeducation+4
1.0k2 years ago
TerraformGoat preview

TerraformGoat

GitHubhxsecurity/terraformgoat

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

cloud-infrastructure-securitycloud-securityeducation+2
6403 years ago
365-Stealer preview

365-Stealer

GitHubalteredsecurity/365-stealer

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

cloud-securitypenetration-testingphishing+1
5877 months ago
CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata preview

CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata

GitHubgeorge0papasotiriou/cve-2026-3333-dns-rebinding-to-steal-cloud-metadata

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

cloud-securitydata-exfiltrationexploitation+4
2 months ago
agent-bom preview

agent-bom

GitHubmsaad00/agent-bom

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

ai-securitycloud-securitycontainer-security+6
3115 hours ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
Azure-AccessPermissions preview
Archived

Azure-AccessPermissions

GitHubcsandker/azure-accesspermissions

PowerShell script to enumerate Azure Active Directory access permissions, including role assignments, service principals, and privileged access…

authentication-authorizationcloud-infrastructure-securitycloud-security+4
1103 years ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5473 years ago
f8x preview

f8x

GitHubffffffff0x/f8x

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

cloud-securityctfdevsecops+7
2.2k2 months ago
AzureAttackKit preview

AzureAttackKit

GitHubzephrfish/azureattackkit

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

cloud-securitycurated-resourcesexploitation+6
792 months ago
CVE-2017-10617 preview

CVE-2017-10617

GitHubgteissier/cve-2017-10617

Proof-of-concept exploit for Juniper Contrail XXE vulnerability (CVE-2017-10617) with Docker-based lab environment demonstrating local file…

cloud-securityeducationexploitation+3
57 years ago
CVE-2021-38647-POC-and-Demo-environment preview

CVE-2021-38647-POC-and-Demo-environment

GitHubsimenbai/cve-2021-38647-poc-and-demo-environment

OMIGod / CVE-2021-38647 POC and Demo environment

cloud-securityeducationexploitation+3
35 years ago
CVE-2026-26720-Twenty-RCE preview

CVE-2026-26720-Twenty-RCE

GitHubdillonkirsch/cve-2026-26720-twenty-rce

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

cloud-securitycode-analysisexploitation+3
8 months ago
Honeypot_Smart_Infrastructure preview

Honeypot_Smart_Infrastructure

GitHubadarkst/honeypot_smart_infrastructure

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

cloud-securitycontainer-securityeducation+4
12 years ago
wardn preview

wardn

GitHubrohansx/wardn

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

api-securityauthentication-authorizationcloud-security+6
363 days ago
kata-cve-2020-2023-poc preview

kata-cve-2020-2023-poc

GitHubssst0n3/kata-cve-2020-2023-poc

Proof-of-concept exploit for Kata Containers container escape (CVE-2020-2023) using mknod to modify guest filesystem and overwrite system binaries…

cloud-securitycontainer-escapecontainer-security+3
33 years ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
121 month ago
Previous12…38Next