Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
CVE-2026-28496 preview

CVE-2026-28496

GitHubivanesk315/cve-2026-28496

Docker lab reproducing the FOSSBilling pre-auth RCE chain (CVE-2026-27604 auth bypass + CVE-2026-28496 Twig SSTI) with a Python PoC and patched…

educationexploitationlabs-practice+6
4 days ago
semgrep preview

semgrep

GitHubsemgrep/semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

api-securityapi-security-testingcode-analysis+9
16.6k3 days ago
stratus-red-team preview

stratus-red-team

GitHubdatadog/stratus-red-team

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

adversarial-attackcloud-infrastructure-securitycloud-security+5
2.4k2 days ago
cloudfox preview

cloudfox

GitHubbishopfox/cloudfox

Automating situational awareness for cloud penetration tests.

cloud-infrastructure-securitycloud-securityexploitation+7
2.6k24 days ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5473 years ago
DVFaaS-Damn-Vulnerable-Functions-as-a-Service preview

DVFaaS-Damn-Vulnerable-Functions-as-a-Service

GitHubwe45/dvfaas-damn-vulnerable-functions-as-a-service

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

cloud-securityeducationlabs-practice+1
1373 years ago
CVE-2026-21002-Serverless-Cold-Start-Credential-Leakage-via-Reused-tmp preview

CVE-2026-21002-Serverless-Cold-Start-Credential-Leakage-via-Reused-tmp

GitHubgeorge0papasotiriou/cve-2026-21002-serverless-cold-start-credential-leakage-via-reused-tmp

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

cloud-infrastructure-securitycloud-securitydata-exfiltration+4
1 month ago
pacu preview

pacu

GitHubrhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

cloud-infrastructure-securitycloud-securitydata-exfiltration+7
5.3k5 months ago
cloudgoat preview

cloudgoat

GitHubrhinosecuritylabs/cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

cloud-securityctfeducation+5
3.7k5 months ago
binaryalert preview

binaryalert

GitHubairbnb/binaryalert

BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

cloud-securitydefensive-toolsmalware-analysis+2
1.5k6 years ago
capsule preview

capsule

GitHubcapsulerun/capsule

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

ai-securitycloud-securitycontainer-security+5
2942 months ago
Serverless-Goat preview

Serverless-Goat

GitHubowasp/serverless-goat

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

cloud-securityeducationlabs-practice+3
3317 years ago
Serverless-Top-10-Project preview

Serverless-Top-10-Project

GitHubowasp/serverless-top-10-project

OWASP Serverless Top 10

cloud-securitycurated-resourceseducation+3
2176 years ago
CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite preview

CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite

GitHubgeorge0papasotiriou/cve-2026-9999-serverless-event-injection-to-code-overwrite

Proof-of-concept exploit for CVE-2026-9999, demonstrating path traversal in serverless object storage events that overwrites function source code to…

cloud-infrastructure-securitycloud-securityeducation+3
1 month ago
CVE-2026-23007-Serverless-Cold-Start-Memory-Remanence-Data-Leakage- preview

CVE-2026-23007-Serverless-Cold-Start-Memory-Remanence-Data-Leakage-

GitHubgeorge0papasotiriou/cve-2026-23007-serverless-cold-start-memory-remanence-data-leakage-

Simulates CVE-2026-23007 serverless cold-start memory remanence; demonstrates how persistent global state across Lambda invocations can leak secrets…

cloud-securityeducationexploitation+2
1 month ago
roninforge-hono preview

roninforge-hono

GitHubroninforge/roninforge-hono

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

api-securitycloud-securitycode-analysis+8
3 months ago
LambdaGuard preview
Archived

LambdaGuard

GitHubskyscanner/lambdaguard

AWS Serverless Security

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
4004 years ago
AlertResponder preview
Archived

AlertResponder

GitHubm-mizutani/alertresponder

Automatic security alert response framework by AWS Serverless Application Model

cloud-securitydefensive-toolsincident-response+2
146 years ago
Previous12Next