Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
core preview

core

GitHubopnsense/core

OPNsense GUI, API and systems backend

api-securitycaptcha-bypassconfiguration-auditing+4
4.7k11h 9m ago
PentestingEverything preview

PentestingEverything

GitHubm14r41/pentestingeverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

api-securitycloud-securityctf+9
2.1k14h 49m ago
DOMPurify preview

DOMPurify

GitHubcure53/dompurify

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

api-securitycode-analysisdefensive-tools+3
17.4k16h 23m ago
Claude-BugHunter preview

Claude-BugHunter

GitHubelementalsouls/claude-bughunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

api-securitycloud-securitycurated-resources+8
4.3k19h 35m ago
noir preview

noir

GitHubowasp-noir/noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

api-securitydevsecopspenetration-testing+3
1.4k0 days ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.1k1 day ago
opentaint preview

opentaint

GitHubseqra/opentaint

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

ai-securityapi-securitycode-analysis+7
1542 days ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k2 days ago
agent-vault preview

agent-vault

GitHubinfisical/agent-vault

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

ai-securityapi-securityauthentication-authorization+3
2.2k3 days ago
semgrep preview

semgrep

GitHubsemgrep/semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

api-securityapi-security-testingcode-analysis+9
16.5k3 days ago
ephemora-cell preview

ephemora-cell

GitHubmichaels1011/ephemora-cell

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

ai-securityapi-securitycloud-security+4
113 days ago
mcp-stdio-shellguard preview

mcp-stdio-shellguard

GitHubstudiomeyer-io/mcp-stdio-shellguard

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

api-securitycode-analysisdevsecops+5
5 days ago
CVE-2026-13736 preview

CVE-2026-13736

GitHubminhhk68/cve-2026-13736

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

api-securityexploitationinformation-gathering+3
15 days ago
SentryPeer preview

SentryPeer

GitHubsentrypeer/sentrypeer

Distributed SIP honeypot that detects and shares fraud data on VoIP attacks. Collects bad actor IPs and phone numbers via peer-to-peer network, with…

api-securitynetwork-securitythreat-intelligence
21118 days ago
CVE-2026-19478-PoC preview

CVE-2026-19478-PoC

GitHubdavkharrr/cve-2026-19478-poc

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

api-securityexploitationinformation-gathering+3
1119 days ago
CVE-2026-19650-CVE-2026-19478 preview

CVE-2026-19650-CVE-2026-19478

GitHubhorkimhab/cve-2026-19650-cve-2026-19478

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

api-securityeducationexploitation+4
20 days ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
53325 days ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
1 month ago
Previous1234Next