Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
pipelock preview

pipelock

GitHubluckypipewrench/pipelock

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

ai-securityapi-securitycloud-security+8
835
4 hours ago
brpc preview

brpc

GitHubapache/brpc

Industrial-grade C++ RPC framework for building high-performance distributed systems, supporting multiple protocols (HTTP, gRPC, Redis, Thrift) with…

api-securitycloud-securitygeneral-purpose-utilities+3
17.6k22h 6m ago
resterm preview

resterm

GitHubunkn0wn-root/resterm

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

api-security-testingcloud-securitydevsecops+3
1.9k1 day ago
agent-vault preview

agent-vault

GitHubinfisical/agent-vault

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

ai-securityapi-securityauthentication-authorization+3
2.2k4 days ago
cloudflared preview

cloudflared

GitHubcloudflare/cloudflared

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

api-securitycloud-infrastructure-securitycloud-security+3
15.5k4 days ago
knocker preview

knocker

GitHubfariszr/knocker

Knocker, a knock based access control service for your homelab

api-securityauthenticationcloud-security+2
13511 days ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.0k21 days ago
NGINX_2026_CVE_Bundle_CTI_Report preview

NGINX_2026_CVE_Bundle_CTI_Report

GitHubchpratik/nginx_2026_cve_bundle_cti_report

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

cloud-securitycurated-resourceseducation+6
1 month ago
CVE-2026-24207 preview

CVE-2026-24207

GitHuboffseckit/cve-2026-24207

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

authenticationcloud-securitycommand-and-control+8
12 months ago
NGINX-Rift preview

NGINX-Rift

GitHubnu0l/nginx-rift

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

cloud-securityconfiguration-auditingcontainer-security+3
53 months ago
CVE-2025-9074-Docker-Desktop-API-Escape-PoC preview

CVE-2025-9074-Docker-Desktop-API-Escape-PoC

GitHubmedaz-sploit/cve-2025-9074-docker-desktop-api-escape-poc

Proof-of-concept exploit for CVE-2025-9074 enabling Docker Desktop API escape via raw HTTP requests. Provides an emulated interactive shell inside a…

cloud-securitycontainer-escapeexploitation+3
3 months ago
mhr-cfw preview

mhr-cfw

GitHubdenuitt1/mhr-cfw

A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

cloud-securityids-ips-evasionred-teaming+1
4.4k4 months ago
CVE-2026-40175 preview

CVE-2026-40175

GitHub0xblackash/cve-2026-40175

CVE-2026-40175

cloud-securityeducationexploitation+3
4 months ago
CVE-2026-29954 preview

CVE-2026-29954

GitHubb0b0haha/cve-2026-29954

Proof-of-concept demonstrating SSRF and HTTP header injection in KubePlus ResourceComposition, enabling cloud metadata access and IAM credential…

cloud-securityexploitationpenetration-testing+2
5 months ago
CVE-2026-29955 preview

CVE-2026-29955

GitHubb0b0haha/cve-2026-29955

Proof-of-concept for CVE-2026-29955, a command injection vulnerability in KubePlus kubeconfiggenerator allowing remote code execution and…

cloud-securitycontainer-securityexploitation+3
5 months ago
SharePointDumper preview

SharePointDumper

GitHubzh54321/sharepointdumper

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

authenticationcloud-securitydata-exfiltration+7
1677 months ago
CVE-2025-63571 preview

CVE-2025-63571

GitHubrrespxwnss/cve-2025-63571

Proof of concept demonstrating Server-Side Request Forgery in ChatGPT, allowing attackers to force the AI to make arbitrary HTTP requests, exposing…

cloud-securityexploitationinformation-gathering+3
9 months ago
cve-2025-9074-poc preview

cve-2025-9074-poc

GitHubxrayzen/cve-2025-9074-poc

2025年8月20日に公開されたDockerDesktopの脆弱性(対策済み)を実証する

cloud-securitycontainer-securityeducation+3
1 year ago
Previous12Next