Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1297 results
geiger preview

geiger

GitHubatomburstofficial/geiger

Read-only CLI that inventories AI agents, MCP servers, plugins, and extensions on a machine, reporting their capabilities and exposure with…

ai-securitycloud-securityconfiguration-auditing+2
19
2 days ago
openshield preview

openshield

GitHubowasp/openshield

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

cloud-securityconfiguration-auditingcryptography+4
564 days ago
CVE-2026-62201-OpenClaw-SSRF preview

CVE-2026-62201-OpenClaw-SSRF

GitHubdiedromeo/cve-2026-62201-openclaw-ssrf

Deep-dive analysis of CVE-2026-62201: OpenClaw sandbox exec-server network policy bypass (SSRF). Root cause, vulnerable vs patched code,…

cloud-securityexploitationvulnerability-analysis+1
3 days ago
sast-scan-action preview

sast-scan-action

GitHuboffensive360/sast-scan-action

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

api-security-testingcloud-securitycode-analysis+4
1 month ago
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

api-security-testingcloud-securitycode-analysis+3
1 month ago
CyberStrikeAI preview

CyberStrikeAI

GitHubaipentest/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+8
6.4k17 days ago
syswarden preview

syswarden

GitHubduggytuxy/syswarden

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

cloud-securityconfiguration-auditingdefensive-tools+4
3295 days ago
gha-lab-8aba6b05dc preview

gha-lab-8aba6b05dc

GitHubpvharmo2/gha-lab-8aba6b05dc

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of…

cloud-securitycurated-resourceseducation+3
5 days ago
gha-lab-5511dc3f73 preview

gha-lab-5511dc3f73

GitHubpvharmo2/gha-lab-5511dc3f73

Authorized security-research lab reproducing CVE-2026-45131 (pwn request in .github/workflows/pull-request.yaml) — snapshot of…

cloud-securitydevsecopseducation+2
5 days ago
CVE-2026-44578-next-js-ssrf preview

CVE-2026-44578-next-js-ssrf

GitHubisaca0315/cve-2026-44578-next-js-ssrf

este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah

cloud-securityctfexploitation+4
5 days ago
pigeon preview

pigeon

GitHubpigeonlabshq/pigeon

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

ai-securityapi-securityauthentication-authorization+3
76 days ago
ephemora-cell preview

ephemora-cell

GitHubmichaels1011/ephemora-cell

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

ai-securityapi-securitycloud-security+4
1716h 49m ago
gha-lab-3f1ff30e9c preview

gha-lab-3f1ff30e9c

GitHubpvharmo2/gha-lab-3f1ff30e9c

Authorized security-research lab reproducing CVE-2026-31852 (jellyfin/jellyfin-ios pull_request_target pwn in code-quality.yml) — isolated snapshot,…

cloud-securitycurated-resourcesdevsecops+2
7 days ago
gha-lab-fb6df3d456 preview

gha-lab-fb6df3d456

GitHubpvharmo2/gha-lab-fb6df3d456

Authorized security-research lab reproducing CVE-2025-46820 (GHSA-cwj7-6v67-2cm4): GITHUB_TOKEN persisted into publicly downloadable CI artifacts in…

cloud-securitycurated-resourceseducation+2
18 days ago
gha-lab-2f775f277c preview

gha-lab-2f775f277c

GitHubpvharmo2/gha-lab-2f775f277c

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

cloud-securitycurated-resourcesdevsecops+2
8 days ago
jiopc-architecture-whitepaper preview

jiopc-architecture-whitepaper

GitHubsys-dissect/jiopc-architecture-whitepaper

Technical whitepaper dissecting JioPC cloud VDI architecture, including hardware specs, session termination mechanisms, and security limitations,…

cloud-securitycurated-resourceseducation+4
248 days ago
CVE-2026-82329-poc preview

CVE-2026-82329-poc

GitHubgagaltotal/cve-2026-82329-poc

PoC and validation tool for CVE-2026-82329 in JFrog Artifactory. Forges JWT with empty signing key to obtain admin token, verifies access, and…

authenticationcloud-securityexploitation+3
8 days ago
gha-lab-becf103a54 preview

gha-lab-becf103a54

GitHubpvharmo2/gha-lab-becf103a54

Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration…

cloud-securitycurated-resourceseducation+2
9 days ago
Previous12…73Next