Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
DVFaaS-Damn-Vulnerable-Functions-as-a-Service preview

DVFaaS-Damn-Vulnerable-Functions-as-a-Service

GitHubwe45/dvfaas-damn-vulnerable-functions-as-a-service

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

cloud-securityeducationlabs-practice+1
137
3 years ago
eternalblue-ms17-010-research preview

eternalblue-ms17-010-research

GitHubtrinadh-dasari-cyber/eternalblue-ms17-010-research

Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK…

educationexploitationlabs-practice+3
3 months ago
BlueCloud preview

BlueCloud

GitHubiknowjason/bluecloud

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

cloud-infrastructure-securitycloud-securitydefensive-tools+7
1493 years ago
LOAD preview

LOAD

GitHub0xballpoint/load

Lord Of Active Directory - automatic vulnerable active directory on AWS

cloud-infrastructure-securityeducationlabs-practice+3
1562 years ago
KaiMonkey preview

KaiMonkey

GitHubtenable/kaimonkey

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

cloud-infrastructure-securitycloud-securityeducation+3
1072 years ago
DEFCON-CICD-pipelines-workshop preview

DEFCON-CICD-pipelines-workshop

GitHubwavestone-cdt/defcon-cicd-pipelines-workshop

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

cloud-securitycontainer-escapecontainer-security+8
933 years ago
awesome-web-security preview

awesome-web-security

GitHubqazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

ctfcurated-resourceseducation+7
13.8k3 days ago
awesome-devsecops preview

awesome-devsecops

GitHubdevsecops/awesome-devsecops

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

curated-resourcesdevsecopseducation+7
5.5k4 years ago
DetectionLab preview

DetectionLab

GitHubclong/detectionlab

Automate the creation of a lab environment complete with security tooling and logging best practices

configuration-auditingdefensive-toolsdigital-forensics+5
5.0k3 years ago
WhatTheHack preview

WhatTheHack

GitHubmicrosoft/whatthehack

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

ai-securitycloud-infrastructure-securitycloud-security+6
1.9k2 months ago
metarget preview

metarget

GitHubmetarget/metarget

Metarget is a framework providing automatic constructions of vulnerable infrastructures.

cloud-securitycontainer-securityeducation+4
1.4k1 month ago
BadZure preview

BadZure

GitHubmvelazc0/badzure

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

cloud-securityctfeducation+6
52412 days ago
htb-writeups preview

htb-writeups

GitHubmomenbasel/htb-writeups

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

ctfcurated-resourceseducation+7
2421 month ago
cybersecurity-projects preview

cybersecurity-projects

GitHubosxninja/cybersecurity-projects

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

ai-securitycurated-resourcesdigital-forensics+7
271 month ago
subpath-exploit preview

subpath-exploit

GitHubbgeesaman/subpath-exploit

Writeup of CVE-2017-1002101 with sample "exploit"/escape

cloud-securitycontainer-escapeeducation+3
348 years ago
hardening-k8s-containers preview

hardening-k8s-containers

GitHubcyberhades/hardening-k8s-containers

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…

cloud-securitycontainer-securityeducation+2
56 years ago
From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps preview

From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps

GitHubmrk336/from-foothold-to-domain-admin-weaponizing-cve-2025-54918-in-real-world-devops

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

cloud-securityconfiguration-auditingdevsecops+7
411 months ago
CVE-2026-34040-PoC preview

CVE-2026-34040-PoC

GitHubm0nk3ygod/cve-2026-34040-poc

Lab reproduction of CVE-2026-34040: bypasses Docker/Moby AuthZ plugins using oversized (>1MB) request bodies to create privileged containers with…

cloud-infrastructure-securitycontainer-securityeducation+3
3 months ago
Previous1234567Next