Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DevSecOps | Kitploit
Categories

DevSecOps

Security integration in CI/CD pipelines, shift-left, and DevOps security automation tools.

Kitploit recommended

Top tools

10 selected
trivy preview#1

trivy

GitHubaquasecurity/trivy
37.4k13h 16m ago
semgrep preview#2

semgrep

GitHubsemgrep/semgrep
16.2k11 days ago
gitleaks preview#3

gitleaks

GitHubgitleaks/gitleaks
28.6k2 months ago
trufflehog preview#4

trufflehog

GitHubtrufflesecurity/trufflehog
27.4k5 days ago
checkov preview#5

checkov

GitHubbridgecrewio/checkov
8.9k4 days ago
grype preview#6

grype

GitHubanchore/grype
12.7k3 days ago
syft preview#7

syft

GitHubanchore/syft
9.6k3 days ago
dependency-track preview#8

dependency-track

GitHubdependencytrack/dependency-track
4.1k13h 28m ago
DependencyCheck preview#9

DependencyCheck

GitHubdependency-check/dependencycheck
7.7k2 days ago
osv-scanner preview#10

osv-scanner

GitHubgoogle/osv-scanner
10.8k4 days ago
NewestRelevanceMost popularRecently updated
999 results
owasp-ctf-in-a-box preview

owasp-ctf-in-a-box

GitHubowasp/owasp-ctf-in-a-box

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

container-securityvulnerability-analysissecurity-virtualization+6
111 day ago
hol-guard preview

hol-guard

GitHubhashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

defensive-toolsstatic-analysisvulnerability-scanners+7
6341 day ago
JavaSecLab preview

JavaSecLab

GitHubwhgojp/javaseclab

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

static-code-analysisvulnerability-analysiscode-analysis+6
8813 months ago
owasp-ctf preview

owasp-ctf

GitHubowasp/owasp-ctf

Self-hosted CTF control plane for security-learning events: team registration, live leaderboard, and patch-to-score, quiz, jeopardy, and AI challenge…

container-securityvulnerability-analysissecurity-virtualization+7
111 day ago
async-http-client-check preview

async-http-client-check

GitHubxiaoqimikko/async-http-client-check

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

defensive-toolsstatic-analysisvulnerability-scanners+4
2 days ago
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

defensive-toolsstatic-analysisvulnerability-scanners+4
91 year ago
evmbench-certora-agent-harness preview

evmbench-certora-agent-harness

GitHubgmh5225/evmbench-certora-agent-harness

Iterative agent harness that uses LLMs and Certora Prover to generate and refine smart-contract CVL specs, feeding verifier output back until success…

defensive-toolsstatic-analysisvulnerability-analysis+4
7 months ago
o1js-scan preview

o1js-scan

GitHubauditinfra-io/o1js-scan

Dependency-free static analyzer for zk circuit soundness bugs in o1js/Mina zkApps and Noir circuits

defensive-toolsstatic-analysisvulnerability-scanners+5
28 days ago
agentic-workflow-injection preview

agentic-workflow-injection

GitHubsushant-me/agentic-workflow-injection

Reproducible vulnerable and fixed GitHub Actions fixtures for agentic workflow injection (CVE-2026-44246), with measured detector coverage and…

static-analysisvulnerability-scannersvulnerability-analysis+4
5 days ago
CanoP preview

CanoP

GitHubopenbreach/canop

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

defensive-toolsstatic-analysisvulnerability-scanners+7
28 days ago
Responsible-Alliance-Protocol preview

Responsible-Alliance-Protocol

GitHubphilippeabraxas-jpg/responsible-alliance-protocol

Safety cannot be a prompt instruction. TBP provides an external execution-layer boundary for autonomous agents, enforcing hard F/I/W invariants via…

authentication-authorizationdefensive-toolsconfiguration-auditing+7
7 days ago
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

vulnerability-scannerscontainer-securitynetwork-mapping+8
19 days ago
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

authentication-authorizationdefensive-toolscontainer-security+7
8.6k6 days ago
Aegis-releases preview

Aegis-releases

GitHubadarsh14734/aegis-releases

Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and…

authentication-authorizationdefensive-toolsconfiguration-auditing+5
6 days ago
agent preview

agent

GitHubbomfather/agent

eBPF-based Linux agent that enforces executable-level access policies in kernel space, sandboxing processes and restricting file, network, and GPU…

defensive-toolscontainer-securityconfiguration-auditing+2
287 days ago
CVE-2026-24733 preview

CVE-2026-24733

GitHubdarabium/cve-2026-24733

Dependency-free Python verifier that detects CVE-2026-24733, an Apache Tomcat HTTP/0.9 HEAD security-constraint bypass, with JSON output and CI/CD…

defensive-toolsvulnerability-scannersvulnerability-analysis+4
6 days ago
runeward preview

runeward

GitHubrunewardd/runeward

Governed execution cells for AI agents.

authentication-authorizationdefensive-toolscontainer-security+7
12 days ago
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

static-code-analysisvulnerability-analysiscode-analysis+4
7 days ago
Previous12…56Next