Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
819 results
CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath preview

CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath

GitHubgeorge0papasotiriou/cve-2026-21008-kubernetes-service-account-token-mounted-in-hostpath

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

cloud-infrastructure-securitycloud-securitycontainer-security+4
1 month ago
CVE-2019-1002101-Helpers preview

CVE-2019-1002101-Helpers

GitHubbrompwnie/cve-2019-1002101-helpers

PoC helper scripts and Dockerfile for CVE-2019-1002101

cloud-securitycontainer-securityexploitation+3
67 years ago
spire preview

spire

GitHubspiffe/spire

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

authenticationauthentication-authorizationcloud-infrastructure-security+5
2.5k21h 52m ago
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

api-security-testingauthentication-authorizationcontainer-security+3
120 days ago
kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed preview

kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed

GitHubshoucheng3/kubernetes-client__java_cve-2020-8570_client-java-parent-9_0_2_fixed

Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

api-securityauthentication-authorizationcloud-infrastructure-security+3
9 months ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.9k14 days ago
awesome-security-hardening preview

awesome-security-hardening

GitHubdecalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

cloud-securityconfiguration-auditingcontainer-security+6
6.5k4 months ago
varc preview
Archived

varc

GitHubcado-security/varc

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

cloud-securitycontainer-securitydigital-forensics+3
2541 year ago
Awesome-CloudSec-Labs preview

Awesome-CloudSec-Labs

GitHubiknowjason/awesome-cloudsec-labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

cloud-securitycontainer-securityctf+7
2.2k11 months ago
exploit-CVE-2017-7494 preview

exploit-CVE-2017-7494

GitHubopsxcq/exploit-cve-2017-7494

SambaCry exploit and vulnerable container (CVE-2017-7494)

container-securityexploitationpayload-development+3
3803 years ago
CyberStrikeAI preview

CyberStrikeAI

GitHubed1s0nz/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+9
6.4k9h 54m ago
docker-bench-security preview

docker-bench-security

GitHubdocker/docker-bench-security

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

configuration-auditingcontainer-securitydevsecops+1
9.7k3 months ago
cve-2019-5736-poc preview

cve-2019-5736-poc

GitHubq3k/cve-2019-5736-poc

Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)

container-escapecontainer-securityexploitation+2
2107 years ago
abstractshimmer preview

abstractshimmer

GitHubnccgroup/abstractshimmer

Proof of concept for CVE-2020-15257 in containerd.

cloud-securitycontainer-escapecontainer-security+3
185 years ago
Honeypot_Smart_Infrastructure preview

Honeypot_Smart_Infrastructure

GitHubadarkst/honeypot_smart_infrastructure

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

cloud-securitycontainer-securityeducation+4
12 years ago
CVE-2025-1974 preview

CVE-2025-1974

GitHub0xbingo/cve-2025-1974

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

cloud-securitycontainer-securityeducation+4
1 year ago
CyberStrikeAI preview

CyberStrikeAI

GitHubaipentest/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+8
6.4k13 days ago
CVE-2023-36723 preview

CVE-2023-36723

GitHubwh04m1001/cve-2023-36723

Proof-of-concept exploit for CVE-2023-36723, an arbitrary directory creation vulnerability in Windows Container Manager, enabling privilege…

container-securityexploitationlateral-movement+2
672 years ago
Previous12…46Next