Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
149 results
JShielder preview

JShielder

GitHubjsitech/jshielder

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

configuration-auditingdevsecopshardware-security+7
783
7 years ago
checkov preview

checkov

GitHubbridgecrewio/checkov

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

cloud-securitycode-analysiscontainer-security+6
9.0k2 days ago
gixy preview

gixy

GitHubyandex/gixy

Nginx configuration static analyzer

configuration-auditingdevsecopsmisconfiguration+3
8.6k2 years ago
security_monkey preview
Archived

security_monkey

GitHubnetflix/security_monkey

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
4.4k5 years ago
CloudFlair preview

CloudFlair

GitHubchristophetd/cloudflair

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

dns-subdomain-enumerationinformation-gatheringmisconfiguration+3
3.0k1 year ago
linuxprivchecker preview

linuxprivchecker

GitHubsleventyeleven/linuxprivchecker

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

ctfeducationinformation-gathering+3
1.8k5 years ago
Corsy preview

Corsy

GitHubs0md3v/corsy

CORS Misconfiguration Scanner

misconfigurationvulnerability-scannersweb-security
1.5k4 years ago
LeakLooker preview
Archived

LeakLooker

GitHubwoj-ciech/leaklooker

Find open databases - Powered by Binaryedge.io

cloud-securitydatabase-securityinformation-gathering+5
1.5k6 years ago
Windows-Local-Privilege-Escalation-Cookbook preview

Windows-Local-Privilege-Escalation-Cookbook

GitHubnickvourd/windows-local-privilege-escalation-cookbook

Windows Local Privilege Escalation Cookbook

configuration-auditingeducationexploitation+9
1.4k6 months ago
power-pwn preview

power-pwn

GitHubmbrg/power-pwn

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

ai-securitycloud-securityinformation-gathering+8
1.2k8 months ago
jdwp-shellifier preview

jdwp-shellifier

GitHubioactive/jdwp-shellifier
debuggersexploitationmisconfiguration+1
9172 years ago
sast-scan preview

sast-scan

GitHubshiftleftsecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

cloud-securitycode-analysisconfiguration-auditing+6
8792 years ago
aws-inventory preview

aws-inventory

GitHubnccgroup/aws-inventory

Discover resources created in an AWS account.

cloud-infrastructure-securitycloud-securitymisconfiguration
7372 years ago
CORStest preview

CORStest

GitHubrub-nds/corstest

A simple CORS misconfiguration scanner

misconfigurationpenetration-testingvulnerability-scanners+1
4246 years ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
BlobHunter preview

BlobHunter

GitHubcyberark/blobhunter

Find exposed data in Azure with this public blob scanner

cloud-infrastructure-securitycloud-securityinformation-gathering+2
3582 years ago
ADenum preview

ADenum

GitHubsecuproject/adenum

AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with kerberos.

misconfigurationpassword-crackingpenetration-testing
3183 years ago
megplus preview
Archived

megplus

GitHubedoverflow/megplus

Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]

crawlerinformation-gatheringmisconfiguration+5
3037 years ago
Previous12…9Next