Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
prowler preview

prowler

GitHubprowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+10
15.0k
1 day ago
firecracker preview

firecracker

GitHubfirecracker-microvm/firecracker

Secure and fast microVMs for serverless computing.

cloud-infrastructure-securitycloud-securitycontainer-security+3
37.2k16 days ago
trivy preview

trivy

GitHubaquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

cloud-infrastructure-securitycloud-securitycode-analysis+14
38.3k1 day ago
SyntheticSun preview

SyntheticSun

GitHubjonrau1/syntheticsun

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

anomaly-detectioncloud-securityincident-response+3
825 years ago
pyrasp preview

pyrasp

GitHubrbidou/pyrasp

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

ai-securityanomaly-detectionapi-security+6
394 days ago
cloudgoat preview

cloudgoat

GitHubrhinosecuritylabs/cloudgoat

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

cloud-securityctfeducation+5
3.8k6 months ago
serverless-application-model preview

serverless-application-model

GitHubaws/serverless-application-model

Transforms SAM templates into CloudFormation resources, generating Lambda functions, IAM roles, and policies with built-in serverless best practices.

cloud-infrastructure-securitycloud-securitydevsecops+1
9.6k5 days ago
checkov preview

checkov

GitHubbridgecrewio/checkov

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

cloud-infrastructure-securitycloud-securitycode-analysis+12
9.1k12h 17m ago
cloud-custodian preview

cloud-custodian

GitHubcloud-custodian/cloud-custodian

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
6.1k5 days ago
ScoutSuite preview

ScoutSuite

GitHubnccgroup/scoutsuite

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
7.8k2 years ago
stratus-red-team preview

stratus-red-team

GitHubdatadog/stratus-red-team

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

adversarial-attackcloud-infrastructure-securitycloud-security+5
2.4k6 days ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5473 years ago
serverless-prey preview

serverless-prey

GitHubpumasecurity/serverless-prey

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

cloud-securityeducationexploitation+5
2481 year ago
capsule preview

capsule

GitHubcapsulerun/capsule

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

ai-securitycloud-securitycontainer-security+5
2983 months ago
AlertResponder preview
Archived

AlertResponder

GitHubm-mizutani/alertresponder

Automatic security alert response framework by AWS Serverless Application Model

cloud-securitydefensive-toolsincident-response+2
146 years ago
LambdaGuard preview
Archived

LambdaGuard

GitHubskyscanner/lambdaguard

AWS Serverless Security

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
4004 years ago