Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
AWS-Key-Hunter preview

AWS-Key-Hunter

GitHubiamlucif3r/aws-key-hunter

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

cloud-securitycode-analysisinformation-gathering+2
40
1 year ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubcontrast-security-oss/cve-2021-44228

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

cloud-securitycode-analysisdevsecops+3
4 months ago
claudleak preview

claudleak

GitHubhazcod/claudleak

Hunt for AI coding artifacts containing secrets.

cloud-securitycode-analysisinformation-gathering+3
576 months ago
CVE-2026-11417-AWS-CDK-RCE preview

CVE-2026-11417-AWS-CDK-RCE

GitHubheshamash/cve-2026-11417-aws-cdk-rce

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

cloud-securitycode-analysiseducation+5
2 months ago
tfsec preview

tfsec

GitHubaquasecurity/tfsec

Tfsec is now part of Trivy

cloud-securitycode-analysisdevsecops+3
7.0k5 months ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.1k1 day ago
AISVS preview

AISVS

GitHubowasp/aisvs

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

adversarial-attackai-securityanomaly-detection+6
4461 day ago
horusec preview

horusec

GitHubzupit/horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

cloud-securitycode-analysiscontainer-security+5
1.3k3 years ago
sast-scan preview

sast-scan

GitHubshiftleftsecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

cloud-securitycode-analysisconfiguration-auditing+6
8793 years ago
react2shell preview

react2shell

GitHubfreeqaz/react2shell

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

code-analysisdynamic-analysis-sandboxingeducation+6
689 months ago
MakerChecker preview

MakerChecker

GitHubmakerchecker/makerchecker

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

ai-securityauthentication-authorizationcloud-security+7
522 months ago
SucoshScanny preview

SucoshScanny

GitHubmustafabilgici/sucoshscanny

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

code-analysissecret-detectionstatic-code-analysis+3
392 years ago
awesome-appsec-interview preview

awesome-appsec-interview

GitHubparasimpaticki/awesome-appsec-interview

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

cloud-securitycode-analysiscryptography+6
307 months ago
CVE-2026-5059-poc preview

CVE-2026-5059-poc

GitHubvenom203020/cve-2026-5059-poc

Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

code-analysisexploitationstatic-analysis+2
4 months ago
CVE-2023-33246-mitigation preview

CVE-2023-33246-mitigation

GitHubpavilionq/cve-2023-33246-mitigation

Maven-based demonstration of CVE-2023-33246 mitigation for Apache RocketMQ, featuring attack testing and enhanced parameter validation to prevent…

cloud-securitycode-analysisexploitation+2
12 years ago
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
27.7k1 day ago
trivy-action preview

trivy-action

GitHubaquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

cloud-securitycode-analysiscontainer-security+5
1.4k26 days ago
gf preview

gf

GitHubtomnomnom/gf

A wrapper around grep, to help you grep for things

code-analysisdynamic-code-analysisgeneral-purpose-utilities+7
2.1k2 years ago
Previous1234Next