Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
PowerShell-Pro-Obfuscator-Python preview

PowerShell-Pro-Obfuscator-Python

GitHubpelock/powershell-pro-obfuscator-python

Automate PowerShell script source code obfuscation & virtualization with a flexible Web API for Python (pip package).

code-analysisscripting-automationutilities-frameworks
2
1 month ago
log4fix preview

log4fix

GitHubnanitor/log4fix

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

code-analysisgeneral-purpose-utilitiesmisconfiguration+3
124 years ago
gobee preview

gobee

GitHubboratanrikulu/gobee

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

binary-analysiscode-analysisdevsecops+3
3484 months ago
mcpguard-dynamic preview

mcpguard-dynamic

GitHubfacebook/mcpguard-dynamic

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

ai-securitycode-analysiscontainer-security+8
742 months ago
mcp-stdio-shellguard preview

mcp-stdio-shellguard

GitHubstudiomeyer-io/mcp-stdio-shellguard

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

api-securitycode-analysisdevsecops+5
7 days ago
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
391 month ago
react2shell preview

react2shell

GitHubcahyod/react2shell

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

code-analysisstatic-analysissupply-chain-security+2
19 months ago
CVE-2026-47670 preview

CVE-2026-47670

GitHuberror-inside/cve-2026-47670

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

code-analysiseducationexploitation+4
3 months ago
are-you-get-tanstack-attack preview

are-you-get-tanstack-attack

GitHubyomisana/are-you-get-tanstack-attack

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

code-analysisstatic-analysissupply-chain-security+1
4 months ago
malware-check preview

malware-check

GitHubmomenbasel/malware-check

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

binary-analysiscode-analysisdevsecops+7
644 months ago
kyubisweep preview

kyubisweep

GitHubtanmayshahane/kyubisweep

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

code-analysisconfiguration-auditingdevsecops+3
48 months ago
ngrev preview

ngrev

GitHubmgechev/ngrev

Tool for reverse engineering of Angular applications

code-analysisreverse-engineeringstatic-code-analysis
1.6k5 years ago
sast-scan preview

sast-scan

GitHubshiftleftsecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

cloud-securitycode-analysisconfiguration-auditing+6
8803 years ago
APKHunt preview

APKHunt

GitHubcyber-buddy/apkhunt

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

android-securitycode-analysismobile-security+3
9791 year ago
autoSource preview

autoSource

GitHubshubhamshubhankar/autosource

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

code-analysisdevsecopsstatic-code-analysis+1
707 years ago
apkinspector preview

apkinspector

GitHubhoneynet/apkinspector

APKinspector is a powerful GUI tool for analysts to analyze the Android applications.

android-securitybinary-analysiscode-analysis+7
85213 years ago
talisman preview

talisman

GitHubthoughtworks/talisman

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

code-analysisdevsecopssecret-detection+1
2.1k10 months ago
njsscan preview

njsscan

GitHubajinabraham/njsscan

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

code-analysisdevsecopsstatic-analysis+3
4541 month ago
Previous12Next