Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
115 results
aws-security-assessment-solution preview

aws-security-assessment-solution

GitHubawslabs/aws-security-assessment-solution

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
623
3 days ago
nord-stream preview

nord-stream

GitHubsynacktiv/nord-stream

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

data-exfiltrationdevsecopsexploitation+5
3741 month ago
yatas preview

yatas

GitHubpadok-team/yatas

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
3433 months ago
h3-cli preview

h3-cli

GitHubhorizon3ai/h3-cli

CLI tool for the Horizon3.ai API

cloud-securitydevsecopspenetration-testing-frameworks+3
261 day ago
azure-security-auditor preview

azure-security-auditor

GitHubneelkotnis/azure-security-auditor

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
11 month ago
whispers preview
Archived

whispers

GitHubskyscanner/whispers

Identify hardcoded secrets in static structured text

code-analysisconfiguration-auditingdevsecops+4
5052 years ago
vault preview

vault

GitHubhashicorp/vault

A tool for secrets management, encryption as a service, and privileged access management

authenticationauthentication-authorizationcloud-security+5
36.2k6h 39m ago
local-log4j-vuln-scanner preview
Archived

local-log4j-vuln-scanner

GitHubhillu/local-log4j-vuln-scanner

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

code-analysisdevsecopsstatic-analysis+3
3714 years ago
sslx preview

sslx

GitHubglincker/sslx

A fast, modern alternative to OpenSSL's CLI - inspect, grade, and manage certificates from the terminal

cryptographydevsecopsencryption-decryption-tools+3
102 days ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.9k10 days ago
testng-team__testng_CVE-2022-4065_7-5 preview

testng-team__testng_CVE-2022-4065_7-5

GitHubshoucheng3/testng-team__testng_cve-2022-4065_7-5

Java testing framework for unit, integration, and end-to-end tests with annotations, data-driven testing, and parallel execution support.

code-analysisdevsecopsgeneral-purpose-utilities
1 year ago
CVE-2024-3094-Vulnerability-Checker-Fixer preview

CVE-2024-3094-Vulnerability-Checker-Fixer

GitHubgensecaihq/cve-2024-3094-vulnerability-checker-fixer

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

cloud-securitydevsecopsmisconfiguration+3
262 years ago
certbot preview

certbot

GitHubcertbot/certbot

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

authentication-authorizationcloud-securityconfiguration-auditing+3
33.2k3 days ago
guarddog preview

guarddog

GitHubdatadog/guarddog

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

code-analysisdevsecopsdynamic-analysis-sandboxing+6
1.2k3 days ago
strix preview

strix

GitHubusestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

ai-securityapi-security-testingcode-analysis+9
60.6k3h 27m ago
git-all-secrets preview

git-all-secrets

GitHubanshumanbh/git-all-secrets

A tool to capture all the git secrets by leveraging multiple open source git searching tools

code-analysisdevsecopsinformation-gathering+1
1.1k7 years ago
secretlint preview

secretlint

GitHubsecretlint/secretlint

Pluggable linting tool to prevent committing credential.

code-analysisdevsecopssecret-detection+1
1.4k1 day ago
jackhammer preview

jackhammer

GitHubolacabs/jackhammer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

code-analysisconfiguration-auditingdevsecops+9
7407 years ago
Previous1234567Next