Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
828 results
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

container-securitydevsecopsdns-subdomain-enumeration+8
14 days ago
bombini preview

bombini

GitHubbombinisecurity/bombini

eBPF Security Monitoring and Sandboxing Agent Based on Aya

container-securitydefensive-toolsintrusion-detection
641 day ago
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

ai-securityauthentication-authorizationcloud-security+7
8.6k1 day ago
portclue preview

portclue

GitHubpbxqdown/portclue

Explain why a Linux TCP port may or may not be reachable

configuration-auditingcontainer-securitydefensive-tools+3
32 days ago
agent preview

agent

GitHubbomfather/agent

eBPF-based Linux agent that enforces executable-level access policies in kernel space, sandboxing processes and restricting file, network, and GPU…

cloud-securityconfiguration-auditingcontainer-security+2
61 day ago
runeward preview

runeward

GitHubrunewardd/runeward

Governed execution cells for AI agents.

ai-securityauthentication-authorizationcloud-security+7
15 days ago
CVE-2026-85706_docker_exp preview

CVE-2026-85706_docker_exp

GitHubflowerwitch/cve-2026-85706_docker_exp

Docker-based reproduction environment and PoC for CVE-2026-85706, demonstrating GitLab LFI bypass via .json suffix and trailing slash path tricks.

container-securityexploitationlabs-practice+4
5 days ago
mxc preview

mxc

GitHubmicrosoft/mxc

Policy-driven, layered isolation and containment

cloud-infrastructure-securityconfiguration-auditingcontainer-security+3
1.3k1 day ago
CyberStrikeAI preview

CyberStrikeAI

GitHubaipentest/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+8
6.6k2 days ago
log4shell-exploitation-detection preview

log4shell-exploitation-detection

GitHubkalidoulabghaly/log4shell-exploitation-detection

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

container-securityeducationexploitation+5
8 days ago
ephemora-cell preview

ephemora-cell

GitHubmichaels1011/ephemora-cell

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

ai-securityapi-securitycloud-security+4
174 days ago
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

cloud-securitycontainer-securityeducation+7
115 days ago
drupalgeddon2-cve-lab preview

drupalgeddon2-cve-lab

GitHubvaibhav91one/drupalgeddon2-cve-lab

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

container-securityeducationlabs-practice+3
17 days ago
CVE-2026-12243-NLTK-PoC preview

CVE-2026-12243-NLTK-PoC

GitHubmorzelowski/cve-2026-12243-nltk-poc

Docker lab demonstrating CVE-2026-12243 path traversal in NLTK before 3.10.0, contrasting vulnerable and patched behavior with a synthetic secret in…

container-securityeducationlabs-practice+2
18 days ago
cved preview

cved

GitHubgit-rep-src/cved

A tool to manage vulnerable docker containers

cloud-infrastructure-securityconfiguration-auditingcontainer-security+2
5 years ago
agentZ preview

agentZ

GitHubaccuknox/agentz

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

ai-securitycloud-securitycontainer-security+3
487 days ago
CVE-2026-39987-Lab preview

CVE-2026-39987-Lab

GitHubrootdirective-sec/cve-2026-39987-lab

Local Docker lab reproducing CVE-2026-39987, a pre-auth RCE in marimo's terminal WebSocket. Compares vulnerable and patched versions with least-harm…

container-securityeducationexploitation+3
14 months ago
block-copyfail preview

block-copyfail

GitHubmrunalp/block-copyfail

BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4

cloud-securitycontainer-securitydefensive-tools+2
14 months ago
Previous12…46Next