Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
security-research preview

security-research

GitHubgoogle/security-research

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

curated-resourceseducationexploitation+3
4.6k
24 days ago
threat-team preview

threat-team

GitHubgoogle/threat-team

No longer maintained. Please refer to Google Threat Intelligence / Virus Total collections.

curated-resourceseducationioc-management+2
664 months ago
chiasmodon preview

chiasmodon

GitHubchiasmod0n/chiasmodon

Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves…

dns-subdomain-enumerationemail-harvestinginformation-gathering+5
7001 year ago
ALFA preview

ALFA

GitHubinvictus-ir/alfa

Automated forensic analysis tool for Google Workspace audit logs. Acquires all log types, maps events to MITRE ATT&CK Cloud Framework, and identifies…

cloud-securitydigital-forensicsforensics+3
1833 days ago
edge preview

edge

GitHubiknowjason/edge

Whois for the Cloud: Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.

cloud-securitydns-analysisinformation-gathering+4
18810 months ago
Daily-dose-of-malware preview

Daily-dose-of-malware

GitHubwoj-ciech/daily-dose-of-malware

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

command-and-controlinformation-gatheringmalware-analysis+2
408 years ago
CVE-2025-10585-The-Chrome-V8-Zero-Day preview

CVE-2025-10585-The-Chrome-V8-Zero-Day

GitHubadityabhatt3010/cve-2025-10585-the-chrome-v8-zero-day

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

educationexploitationpapers-research+3
1311 months ago
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
27.5k7h 35m ago
PCAPdroid preview

PCAPdroid

GitHubemanuele-f/pcapdroid

No-root network monitor, firewall and PCAP dumper for Android

android-securitydns-analysiseducation+8
4.5k1 day ago
standalone_tdo preview

standalone_tdo

GitHubblevene/standalone_tdo
educationinformation-gatheringmachine-learning+3
47 months ago
CVE-2026-11645 preview

CVE-2026-11645

GitHub0xblackash/cve-2026-11645

CVE-2026-11645

educationexploitationincident-response+3
12 months ago
List-CVE-2025-2026 preview

List-CVE-2025-2026

GitHubmagercode/list-cve-2025-2026

Daftar CVE 2025-2026 terupdate

curated-resourceseducationinformation-gathering+3
17 months ago
s3-leaks preview

s3-leaks

GitHubnagwww/s3-leaks

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

cloud-infrastructure-securitycloud-securitycurated-resources+2
4576 days ago
BlueCloud preview

BlueCloud

GitHubiknowjason/bluecloud

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

cloud-infrastructure-securitycloud-securitydefensive-tools+7
1483 years ago
SkyWrapper preview

SkyWrapper

GitHubcyberark/skywrapper

SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

cloud-infrastructure-securitycloud-securityidentity-access-management+3
1075 years ago
log-horizon preview

log-horizon

GitHublnfernux/log-horizon

Microsoft Sentinel SIEM Log Source Analyzer

cloud-infrastructure-securitycloud-securityconfiguration-auditing+4
292 months ago
Cowrie and Grafana Honeypot using Terraform on DigitalOcean preview

Cowrie and Grafana Honeypot using Terraform on DigitalOcean

GitLaboseguera12/cowrie-honeypot-digitalocean

Medium-interaction SSH/Telnet honeypot built with Cowrie, Loki, Promtail, and Grafana - provisioned on DigitalOcean via Terraform with a GitLab CI…

cloud-infrastructure-securitydevsecopslog-analysis+2
13 months ago
opencspm preview
Archived

opencspm

GitHubopencspm/opencspm

Open Cloud Security Posture Management Engine

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
3474 years ago
Previous12Next