Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
69 results
sentrymcp preview

sentrymcp

GitHubzaydmulani09/sentrymcp

A static + runtime security scanner for MCP (Model Context Protocol) servers

ai-securityapi-securitymisconfiguration+3
2 days ago
CVE-2026-19650-CVE-2026-19478 preview

CVE-2026-19650-CVE-2026-19478

GitHubhorkimhab/cve-2026-19650-cve-2026-19478

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

api-securityeducationexploitation+4
3 days ago
CVE-2026-73519-WolfStack-PoC preview

CVE-2026-73519-WolfStack-PoC

GitHubsqueeze440/cve-2026-73519-wolfstack-poc

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

api-securityauthenticationcontainer-security+3
5 days ago
vuln_apps preview

vuln_apps

GitHubclickswave/vuln_apps

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

api-securityeducationlabs-practice+3
112 days ago
aegisagent preview

aegisagent

GitHubhuzjie/aegisagent

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

ai-securityanomaly-detectionapi-security+4
9 days ago
Threat_Model_Examples preview

Threat_Model_Examples

GitHubtaleliyahu/threat_model_examples

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

ai-securityapi-securitycloud-security+6
5151 year ago
CVE-2026-64640 preview

CVE-2026-64640

GitHuboscerd/cve-2026-64640

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…

api-securitycloud-securitydata-exfiltration+5
13 days ago
otto-support preview

otto-support

GitHubbishopfox/otto-support

An implementation of a vulnerable MCP server using mcp-go

api-securityauthentication-authorizationctf+5
194 months ago
ladder preview

ladder

GitHubeverywall/ladder

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

anti-botapi-securityweb-proxies-interception+1
8.8k14 days ago
gatekeeper preview

gatekeeper

GitHubopen-policy-agent/gatekeeper

Kubernetes policy engine with OPA-based admission control, mutation, and audit for enforcing security and compliance configurations.

api-securitycloud-securityconfiguration-auditing+3
4.3k1 day ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.8k7 days ago
CVE-2026-23552 preview

CVE-2026-23552

GitHuboscerd/cve-2026-23552

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

api-securityauthentication-authorizationeducation+3
6 months ago
clawshield-public preview

clawshield-public

GitHubsleuthco/clawshield-public

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

ai-securityapi-securitydefensive-tools+6
1305 months ago
Securekit preview

Securekit

GitLabroxanne_ardary/securekit

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

ai-securityapi-securitycloud-security+5
27 days ago
UAP-protocol preview

UAP-protocol

GitHubrajsidwadkar/uap-protocol

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

api-securityauthentication-authorizationcloud-security+8
12 months ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k1 month ago
Python-Honeypot preview

Python-Honeypot

GitHubowasp/python-honeypot

OWASP Honeypot, Automated Deception Framework.

api-securitycontainer-securitydefensive-tools+4
4821 year ago
fabric8io__kubernetes-client_CVE-2021-4178_5-0-2 preview

fabric8io__kubernetes-client_CVE-2021-4178_5-0-2

GitHubshoucheng3/fabric8io__kubernetes-client_cve-2021-4178_5-0-2
api-securityauthentication-authorizationcloud-infrastructure-security+3
1 year ago
Previous1234Next