Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
130 results
pyrasp preview

pyrasp

GitHubrbidou/pyrasp

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

ai-securityanomaly-detectionapi-security+6
39
2 days ago
llm-security preview

llm-security

GitHubgreshake/llm-security

Proof-of-concept demos and research on indirect prompt injection attacks against application-integrated LLMs, covering data exfiltration, remote…

adversarial-attackai-securitycommand-and-control+7
2.1k1 year ago
AI-FILE preview

AI-FILE

GitHubkyle41111/ai-file

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

ai-securitycommand-and-controldata-exfiltration+7
133 days ago
OWASP-Top-10-Neocloud-and-AI-Data-Center-Security-Risks preview

OWASP-Top-10-Neocloud-and-AI-Data-Center-Security-Risks

GitHubowasp/owasp-top-10-neocloud-and-ai-data-center-security-risks

OWASP framework cataloging the top 10 security risks in neocloud and AI data center infrastructure, covering hardware, networking, isolation,…

ai-securitycloud-securitycontainer-security+8
15 days ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubyym8538/cve-2026-33017

Proof-of-concept exploit for CVE-2026-33017, an unauthenticated RCE in Langflow's build_public_tmp endpoint, injecting a malicious custom component…

ai-securityexploitationpayload-development+6
11 month ago
Deserializer preview

Deserializer

GitHubjoshuaprovoste/deserializer

AST-based Static Code Analyzer with Agentic LLM-Powered Relationship Mapping to discover Python RCE paths and deep deserialization chains on AI, LLM,…

ai-securitycode-analysisexploitation+6
5 days ago
MMSkillRisk preview

MMSkillRisk

GitHubkaill-jlq/mmskillrisk

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

adversarial-attackai-securitydata-exfiltration+7
25 days ago
TRACE preview

TRACE

GitHubzju-llm-safety/trace

Agentic jailbreak framework for LLM-based agents using scheme-based task decomposition, multi-turn disguising strategies, and adaptive self-evolution…

adversarial-attackai-securityexploitation+5
296 days ago
http-terminator preview

http-terminator

GitHubportswigger/http-terminator

AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms…

ai-securityexploitationfuzzing+8
1242 months ago
ai-kubernetes-helm-chart-security preview

ai-kubernetes-helm-chart-security

GitHubsorami-consulting-au/ai-kubernetes-helm-chart-security

Evidence and data for the Sorami technical report on security defaults of 15 AI serving, vector database and MCP Helm charts on Kubernetes.

ai-securitycloud-securityconfiguration-auditing+5
29 days ago
Hexestra preview

Hexestra

GitHubabsllk/hexestra

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

ai-securitycommand-and-controlinformation-gathering+7
823 days ago
deleting-the-trace preview

deleting-the-trace

GitHubusama1002/deleting-the-trace

Experiments for control-token chain-of-thought suppression and parser-leniency attacks on tool-using LLM agents

adversarial-attackai-securityexploitation+3
112 days ago
CVE-2024-37054 preview

CVE-2024-37054

GitHubbardlaudian/cve-2024-37054

Proof-of-concept that poisons MLflow registered models via the REST API, embedding a malicious pickle to trigger RCE when the model is loaded.

ai-securitydefensive-toolsexploitation+6
12 days ago
coactionbrittlemaidenhair51.github.io preview

coactionbrittlemaidenhair51.github.io

GitHubcoactionbrittlemaidenhair51/coactionbrittlemaidenhair51.github.io

Explore and validate CVE-2026-42978 PoC with an integrated AI security tool, multi-protocol terminal, and autonomous agent suite for Windows Push…

ai-securityexploitationpayload-development+4
8 days ago
AgrusScanner preview

AgrusScanner

GitHubnybaywatch/agrusscanner

Windows network reconnaissance scanner with ping sweeps, TCP port scanning, and deep AI/ML service detection for finding shadow AI, rogue LLM…

ai-securitydefensive-toolsinformation-gathering+6
284 days ago
privacy-filter preview

privacy-filter

GitHubopenai/privacy-filter

Bidirectional token-classification model for PII detection and masking in text, with CLI for redaction, evaluation, and finetuning on-premises.

ai-securitydata-exfiltrationdefensive-tools+4
2.7k5 months ago
xalgorix preview

xalgorix

GitHubxalgorix/xalgorix

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

ai-securitydefensive-toolsexploitation+8
1.2k12h 9m ago
sentric-core preview

sentric-core

GitHubfreire007-byte/sentric-core

Autonomous AI agent with its own crypto identity — hunts CVEs, builds exploit labs, validates vulnerabilities (first public PoC of CVE-2026-86283),…

ai-securitycryptographyexploitation+4
20 days ago
Previous12…8Next