Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
oathkeeper preview

oathkeeper

GitHubory/oathkeeper

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

api-securityauthenticationauthentication-authorization+5
3.6k
2 months ago
macOS-enterprise-privileges preview

macOS-enterprise-privileges

GitHubsap/macos-enterprise-privileges

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

authentication-authorizationconfiguration-auditingdefensive-tools+2
2.1k1 day ago
BadBlood preview

BadBlood

GitHubdavidprowe/badblood

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is…

educationidentity-access-managementlabs-practice+1
2.3k3 years ago
conjur preview

conjur

GitHubcyberark/conjur

CyberArk Conjur automatically secures secrets used by privileged users and machine identities

authentication-authorizationcloud-securitydevsecops+3
9522 months ago
iam-vulnerable preview

iam-vulnerable

GitHubbishopfox/iam-vulnerable

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

cloud-securityeducationidentity-access-management+4
5901 year ago
red-shadow preview

red-shadow

GitHublightspin-tech/red-shadow

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

cloud-infrastructure-securitycloud-securityidentity-access-management+3
955 years ago
OpenClawMachines preview

OpenClawMachines

GitHubmathaix/openclawmachines

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

ai-securityauthenticationcloud-security+6
592 months ago
WonkaVision preview

WonkaVision

GitHub0xe7/wonkavision

Detects forged Kerberos tickets by dumping session and ticket data, scoring anomalies, and generating Windows event-log indicators for SIEM-based…

anomaly-detectionauthenticationdefensive-tools+4
893 years ago
private-landing preview

private-landing

GitHubvhscom/private-landing

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

api-securityauthenticationauthentication-authorization+8
795 months ago
OpenSC.tokend preview

OpenSC.tokend

GitHubopensc/opensc.tokend

Tokend module for OS X with support for all cards supported by OpenSC

authenticationcryptographyhardware-security+1
362 years ago
secdim-assurance-drift-challenge preview

secdim-assurance-drift-challenge

GitHubfranklincg/secdim-assurance-drift-challenge

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

api-securityauthentication-authorizationctf+5
29 days ago
wp-secure-mcp preview

wp-secure-mcp

GitHubles-k/wp-secure-mcp

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

ai-securityapi-securityauthentication-authorization+5
8 days ago
abdal-lockbox preview

abdal-lockbox

GitLabprof.shafiei/abdal-lockbox

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

android-securityauthenticationcryptography+5
2 months ago
Azure-AD-Incident-Response-PowerShell-Module preview
Archived

Azure-AD-Incident-Response-PowerShell-Module

GitHubazuread/azure-ad-incident-response-powershell-module

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

cloud-infrastructure-securitycloud-securitydefensive-tools+3
4573 years ago
professional-services preview

professional-services

GitHubgooglecloudplatform/professional-services

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

anomaly-detectionchaos-engineeringcloud-security+5
3.1k5 days ago
secretive preview

secretive

GitHubmaxgoedjen/secretive

Protect your SSH keys with your Mac's Secure Enclave

authenticationencryption-decryption-toolshardware-security+2
9.0k9 days ago
the-bastion preview

the-bastion

GitHubovh/the-bastion

Authentication, authorization, traceability and auditability for SSH accesses.

authentication-authorizationconfiguration-auditingidentity-access-management+4
2.2k11 days ago
freeipa preview

freeipa

GitHubfreeipa/freeipa

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

authenticationauthentication-authorizationcryptography+2
1.3k4 days ago
Previous123Next