Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
alibi preview

alibi

GitHubowasp-noir/alibi

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

api-securitycode-analysisconfiguration-auditing+7
1116 days ago
pigeon preview

pigeon

GitHubpigeonlabshq/pigeon

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

ai-securityapi-securityauthentication-authorization+3
4420 days ago
aegis-latent-core preview

aegis-latent-core

GitHubjuanlunaia/aegis-latent-core

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

ai-securityapi-securitycloud-security+3
182 days ago
cover preview

cover

GitHubdavidcarliez/cover

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

ai-securityapi-securitydefensive-tools+3
4912 days ago
cerbos preview

cerbos

GitHubcerbos/cerbos

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

api-securityauthenticationauthentication-authorization+3
4.6k1 day ago
opa preview

opa

GitHubopen-policy-agent/opa

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

api-securityauthenticationauthentication-authorization+10
12.3k1 day ago
API-Security-Checklist preview

API-Security-Checklist

GitHubshieldfy/api-security-checklist

Checklist of the most important security countermeasures when designing, testing, and releasing your API

api-securityauthentication-authorizationcurated-resources+4
23.3k2 months ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.9k1 month ago
quill-router preview

quill-router

GitHublore-hex/quill-router

TrustedRouter.com repo for secure LLM proxying

api-securityauthentication-authorizationcloud-security+6
238h 6m ago
Nest preview

Nest

GitHubowasp/nest

Your gateway to OWASP. Discover, engage, and help shape the future!

api-securitycurated-resourceseducation+2
4542 days ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
java-html-sanitizer preview

java-html-sanitizer

GitHubowasp/java-html-sanitizer

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

api-securitycode-analysisdefensive-tools+3
95415h 36m ago
ApiHunter preview

ApiHunter

GitHubteycir/apihunter

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

api-securitydevsecopsdynamic-analysis-sandboxing+6
252 months ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.1k14h 7m ago
agent-vault-proxy preview

agent-vault-proxy

GitHubinflightsec/agent-vault-proxy

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

ai-securityapi-securityauthentication+3
3117 days ago
leakish preview

leakish

GitHubqruiqai/leakish

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

anomaly-detectionapi-securitydns-analysis+7
73 months ago
openpcc preview

openpcc

GitHubopenpcc/openpcc

An open-source framework for verifiably private AI inference

ai-securityapi-securityauthentication-authorization+6
9538 months ago
knocker preview

knocker

GitHubfariszr/knocker

Knocker, a knock based access control service for your homelab

api-securityauthenticationcloud-security+2
1361 month ago
Previous123Next