Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
CVE-2025-67923 preview

CVE-2025-67923

GitHubrandomrobbiebf/cve-2025-67923

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

api-securityexploitationvulnerability-analysis+2
5 months ago
Olyx preview

Olyx

GitLabshacode/olyx

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

android-securityapi-securitydns-analysis+7
6 months ago
ibmsecurity preview

ibmsecurity

GitHubibm-security/ibmsecurity

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

api-securityconfiguration-auditingdevsecops+3
511 month ago
mcp-shark preview

mcp-shark

GitHubmcp-shark/mcp-shark

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

ai-securityapi-securityconfiguration-auditing+7
1733 months ago
CheckPoint-CVE-Webscanner preview

CheckPoint-CVE-Webscanner

GitHubwadesweaponshed/checkpoint-cve-webscanner

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using…

api-securityconfiguration-auditingnetwork-security+2
12 months ago
openclaw-dashboard preview

openclaw-dashboard

GitHubtugcantopaloglu/openclaw-dashboard

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

api-securityauthenticationcloud-security+7
6985 months ago
core preview

core

GitHubopnsense/core

OPNsense GUI, API and systems backend

api-securitycaptcha-bypassconfiguration-auditing+4
4.6k8h 19m ago
archerysec preview

archerysec

GitHubarcherysec/archerysec

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

api-securitycode-analysisconfiguration-auditing+5
2.5k1 year ago
f5-waf-enforce-sig-CVE-2021-44228 preview

f5-waf-enforce-sig-CVE-2021-44228

GitHubirgoncalves/f5-waf-enforce-sig-cve-2021-44228

This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device

api-securityconfiguration-auditingdevsecops+3
64 years ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum
api-securitycloud-securityconfiguration-auditing+7
25 months ago
CYBERDUDEBIVASH-ServiceNow-AI-Agent-Audit-Script preview

CYBERDUDEBIVASH-ServiceNow-AI-Agent-Audit-Script

GitHubcyberdudebivash/cyberdudebivash-servicenow-ai-agent-audit-script

This script audits ServiceNow AI Agents for vulnerabilities like CVE-2025-12420, governance gaps, and compliance risks. Powered by CYBERDUDEBIVASH –…

ai-securityapi-securitycloud-security+2
7 months ago
rhuss__jolokia_CVE-2018-1000129_1-4-0 preview

rhuss__jolokia_CVE-2018-1000129_1-4-0

GitHubshoucheng3/rhuss__jolokia_cve-2018-1000129_1-4-0
api-securityconfiguration-auditingdynamic-analysis-sandboxing+2
8 months ago
externalip-webhook preview
Archived

externalip-webhook

GitHubrancher/externalip-webhook

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

api-securitycloud-securityconfiguration-auditing+3
34 years ago
ginger preview

ginger

GitHubhawsec/ginger

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

api-securitydatabase-securityinformation-gathering+3
134 years ago
Damn-Vulnerable-GraphQL-Application preview

Damn-Vulnerable-GraphQL-Application

GitHubdolevf/damn-vulnerable-graphql-application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

api-securityapi-security-testingctf+5
1.7k1 year ago
pentest-mapper preview

pentest-mapper

GitHubportswigger/pentest-mapper

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

api-securityapi-security-testingpenetration-testing+2
1222 years ago
token-proxy preview

token-proxy

GitHubzolderio/token-proxy

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

ai-securityapi-securitycloud-security+6
284 months ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

api-securitycloud-securitydefensive-tools+5
1.6k1 day ago
Previous123Next