Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
615
7 days ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

container-escapectfcurated-resources+9
17 days ago
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k2 months ago
LabS4U2Self preview

LabS4U2Self

GitHubotterhacker/labs4u2self

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

authentication-authorizationdatabase-securityeducation+5
313 years ago
ADSyncDump-BOF preview

ADSyncDump-BOF

GitHubparadoxis/adsyncdump-bof

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

cloud-securityencryption-decryption-toolsidentity-access-management+3
1841 year ago
postgres-bruteforcer preview

postgres-bruteforcer

GitHubrandomrobbiebf/postgres-bruteforcer

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

authenticationdatabase-securityexploitation+2
3 years ago
aad-sso-enum-brute-spray preview

aad-sso-enum-brute-spray

GitHubtreebuilder/aad-sso-enum-brute-spray

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

authentication-authorizationcloud-securityinformation-gathering+3
1934 years ago
EIPP preview

EIPP

GitHubsynacktiv/eipp

Entra ID Password Protection Banned Password Lists

authenticationcloud-securityconfiguration-auditing+4
202 years ago
IPSpinner preview

IPSpinner

GitHubsynacktiv/ipspinner

IPSpinner works as a local proxy that redirects requests through external services.

cloud-securityids-ips-evasionpassword-attacks+3
1251 year ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
GoAWSConsoleSpray preview

GoAWSConsoleSpray

GitHubwhiteoaksecurity/goawsconsolespray

Tool to spray AWS Console IAM Logins

authenticationcloud-securityinformation-gathering+3
364 years ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
11.7k1 month ago
AzureRedOps preview

AzureRedOps

GitHubmr-un1k0d3r/azureredops

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

authenticationcloud-securityexploitation+8
1832 months ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 months ago
ZeroLogon-CVE-2020-1472-lab preview

ZeroLogon-CVE-2020-1472-lab

GitHub100hnomeunome/zerologon-cve-2020-1472-lab

Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)

ctfeducationexploitation+7
11 months ago
apimspray preview

apimspray

GitHubcrtvrffnrt/apimspray

Azure apim mini proxy

cloud-securityinformation-gatheringosint+3
641 month ago
requests-ip-rotator preview

requests-ip-rotator

GitHubge0rg3/requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

crawlerids-ips-evasioninformation-gathering+5
1.7k1 month ago
CredKing preview

CredKing

GitHubustayready/credking

Password spraying using AWS Lambda for IP rotation

authenticationcloud-securityidentity-access-management+3
6708 years ago
Previous12Next