Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
69416 days ago
apimspray preview

apimspray

GitHubcrtvrffnrt/apimspray

Azure apim mini proxy

cloud-securityinformation-gatheringosint+3
641 month ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
11.9k1 month ago
SharpCollection preview

SharpCollection

GitHubflangvik/sharpcollection

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

curated-resourcesexploitationlateral-movement+6
3.0k1 month ago
AzureRedOps preview

AzureRedOps

GitHubmr-un1k0d3r/azureredops

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

authenticationcloud-securityexploitation+8
1832 months ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 months ago
Outpacket preview

Outpacket

GitHubn00py/outpacket

This cheatsheet maps common impacket workflows to their modern alternatives

authenticationcurated-resourceseducation+6
3043 months ago
offensive-azure preview

offensive-azure

GitHubblacklanternsecurity/offensive-azure

Collection of offensive tools targeting Microsoft Azure

cloud-securityinformation-gatheringpassword-attacks+4
2275 months ago
TeamFiltration preview

TeamFiltration

GitHubflangvik/teamfiltration

Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…

authenticationcloud-securitydata-exfiltration+3
1.4k6 months ago
MAAD-AF preview

MAAD-AF

GitHubvectra-ai-research/maad-af

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

adversarial-attackcloud-securitydata-exfiltration+6
4318 months ago
GoMapEnum preview

GoMapEnum

GitHubnodauf/gomapenum

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

cloud-securityemail-harvestinginformation-gathering+4
49311 months ago
ADSyncDump-BOF preview

ADSyncDump-BOF

GitHubparadoxis/adsyncdump-bof

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

cloud-securityencryption-decryption-toolsidentity-access-management+3
1831 year ago
Spray365 preview
Archived

Spray365

GitHubmarkoh17/spray365

Spray365 makes spraying Microsoft accounts (Office 365 / Azure AD) easy through its customizable two-step password spraying approach. The built-in…

authenticationcloud-securityids-ips-evasion+3
3821 year ago
IPSpinner preview

IPSpinner

GitHubsynacktiv/ipspinner

IPSpinner works as a local proxy that redirects requests through external services.

cloud-securityids-ips-evasionpassword-attacks+3
1251 year ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
o365spray preview

o365spray

GitHub0xzdh/o365spray

Username enumeration and password spraying tool aimed at Microsoft O365.

authenticationcloud-securityinformation-gathering+2
1.1k2 years ago
EIPP preview

EIPP

GitHubsynacktiv/eipp

Entra ID Password Protection Banned Password Lists

authenticationcloud-securityconfiguration-auditing+4
212 years ago
CVE-2023-30146 preview

CVE-2023-30146

GitHubl1-0/cve-2023-30146

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

exploitationhardware-iot-securityinformation-gathering+3
33 years ago
Previous12Next