Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
osv-scanner preview

osv-scanner

GitHubgoogle/osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

code-analysiscontainer-securitydevsecops+4
11.0k
1 day ago
nah preview

nah

GitHubmanuelschipper/nah

a guard that blocks catastrophic agent actions

ai-securitycode-analysiscommand-and-control+8
4822 days ago
vm2 preview

vm2

GitHubpatriksimek/vm2

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

code-analysisdynamic-analysis-sandboxingsecurity-virtualization+1
4.1k4 days ago
basalt preview

basalt

GitHubsunnypatell/basalt

World's first hazard checker for NVIDIA Blackwell (sm_120), with an assembler and scheduler matched against their own compiler byte for byte. The…

binary-analysiscode-analysishardware-security+3
911 days ago
sec-af preview

sec-af

GitHubagent-field/sec-af

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

ai-securitycode-analysisdevsecops+7
19722 days ago
graylog-cve-2024-24824-exploit preview

graylog-cve-2024-24824-exploit

GitHubrootkited/graylog-cve-2024-24824-exploit

Proof-of-concept exploit for CVE-2024-24824 demonstrating how an arbitrary class loading primitive can be transformed into remote code execution on…

code-analysiseducationexploitation+3
2 months ago
CVE-2025-70330 preview

CVE-2025-70330

GitHubthemalwareguardian/cve-2025-70330

Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.

binary-analysisbinary-exploitationcode-analysis+7
25 months ago
npm-demo preview

npm-demo

GitHubalonnavon/npm-demo

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

code-analysiseducationvulnerability-analysis+2
6 months ago
CVE-2026-23947-PoC preview

CVE-2026-23947-PoC

GitHubboroeurnprach/cve-2026-23947-poc

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

code-analysisexploitationsupply-chain-security+2
7 months ago
CVE-2025-55182-React2Shell-RCE-POC preview

CVE-2025-55182-React2Shell-RCE-POC

GitHubrat5ak/cve-2025-55182-react2shell-rce-poc

This repository documents research into deserialization behavior within Next.js React Server Components (RSC) using the Flight protocol. It focuses…

code-analysiseducationexploitation+3
29 months ago
Cawdog preview

Cawdog

GitLablycis/cawdog

CAWODOG is a proof-of-concept project demonstrating how to protect Python-based AI models deployed on offline industrial machines. Across three…

ai-securitycode-analysiseducation+6
9 months ago
Fern Pattern Scanner preview

Fern Pattern Scanner

GitLabgitlab-da/tutorials/security-and-governance/custom-scanner-integration/fern-pattern-scanner

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

code-analysisdevsecopseducation+3
52 years ago
CVE-2007-4559 preview

CVE-2007-4559

GitHubdavidholiday/cve-2007-4559

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

code-analysiseducationexploitation+3
3 years ago
CVE-2023-33733 preview

CVE-2023-33733

GitHubc53elyas/cve-2023-33733

Detailed technical write-up and proof-of-concept exploit for CVE-2023-33733, a remote code execution vulnerability in the Reportlab Python library…

code-analysiseducationexploitation+3
1203 years ago
revsync preview

revsync

GitHublunixbochs/revsync

realtime cross-tool collaborative reverse engineering

binary-analysiscode-analysisreverse-engineering
1003 years ago
frelatage preview

frelatage

GitHubrog3rsm1th/frelatage

Coverage-based fuzzer for python applications

code-analysisdynamic-analysis-sandboxingfuzzing+1
2384 years ago
spring-boot-cve-2022-22965 preview

spring-boot-cve-2022-22965

GitHubsnicoll-scratches/spring-boot-cve-2022-22965

Showcase of overridding the Spring Framework version in older Spring Boot versions

code-analysiseducationexploitation+2
4 years ago
log4j-2021-vulnerability-study preview

log4j-2021-vulnerability-study

GitHubotaviokr/log4j-2021-vulnerability-study

This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it…

code-analysiseducationexploitation+2
4 years ago
Previous12Next