Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
241 results
CVE-2026-100835 preview

CVE-2026-100835

GitHubmurrez/cve-2026-100835

Python PoC for CVE-2026-100835: audits Contrast manifests for AllowedChipIDs/AllowedPIIDs, detects versions, and probes Coordinator endpoints to…

authenticationcloud-securitycontainer-security+5
8 days ago
OWASP-Top-10-Neocloud-and-AI-Data-Center-Security-Risks preview

OWASP-Top-10-Neocloud-and-AI-Data-Center-Security-Risks

GitHubowasp/owasp-top-10-neocloud-and-ai-data-center-security-risks

OWASP framework cataloging the top 10 security risks in neocloud and AI data center infrastructure, covering hardware, networking, isolation,…

ai-securitycloud-securitycontainer-security+8
15 days ago
kube-reaper preview

kube-reaper

GitHubstillbigjosh/kube-reaper

Scans Kubernetes clusters from any identity, flags dangerous permissions, and chains them into multi-step escalation paths to cluster compromise.

cloud-securityconfiguration-auditingcontainer-security+9
316 days ago
phantom-grid preview

phantom-grid

GitHubhaidang-infosec/phantom-grid

An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

authentication-authorizationcontainer-securitydata-exfiltration+7
772 months ago
hardstop preview

hardstop

GitHubjoseluispino/hardstop

Reference implementation for "Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution". Out-of-band Epistemic Andon Cord,…

ai-securityanomaly-detectioncloud-security+7
27 days ago
Kestra-cve-2026-53576 preview

Kestra-cve-2026-53576

GitHubatlasvector/kestra-cve-2026-53576

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

container-securityexploitationincident-response+8
10 days ago
CVE-2023-27163-lab preview

CVE-2023-27163-lab

GitHubamulyakaushik/cve-2023-27163-lab

Docker-based lab reproducing CVE-2023-27163 SSRF in Request-Baskets, with exploitation verification, detection script, and network-isolation…

container-securitydefensive-toolseducation+6
14 days ago
CVE-2023-43804 preview

CVE-2023-43804

GitHubdeepanshu-khurana/cve-2023-43804

Containerized three-tier lab reproducing CVE-2023-43804 urllib3 cookie leak via cross-origin redirects, with exploit script and patch verification.

container-securitydefensive-toolseducation+5
14 days ago
-INE_Shivam_Gupta_23104003 preview

-INE_Shivam_Gupta_23104003

GitHubshivamg2004/-ine_shivam_gupta_23104003

CVE-2021-43798 Grafana Unauthenticated Path Traversal - Security Lab | Shivam Gupta | 23104003

container-securityeducationexploitation+5
14 days ago
CVE-2025-32433-LAB preview

CVE-2025-32433-LAB

GitHubdamnkrishna/cve-2025-32433-lab

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without…

container-securityeducationexploitation+6
16 days ago
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

container-securitydevsecopsdns-subdomain-enumeration+8
110 days ago
bombini preview

bombini

GitHubbombinisecurity/bombini

eBPF Security Monitoring and Sandboxing Agent Based on Aya

container-securitydefensive-toolsintrusion-detection
726 days ago
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

ai-securityauthentication-authorizationcloud-security+7
12.4k4 days ago
portclue preview

portclue

GitHubpbxqdown/portclue

Explain why a Linux TCP port may or may not be reachable

configuration-auditingcontainer-securitydefensive-tools+3
36 days ago
agent preview

agent

GitHubbomfather/agent

eBPF-based Linux agent that enforces executable-level access policies in kernel space, sandboxing processes and restricting file, network, and GPU…

cloud-securityconfiguration-auditingcontainer-security+2
2814 days ago
mxc preview

mxc

GitHubmicrosoft/mxc

Policy-driven, layered isolation and containment

cloud-infrastructure-securityconfiguration-auditingcontainer-security+3
1.4k6 days ago
CyberStrikeAI preview

CyberStrikeAI

GitHubaipentest/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+8
7.1k10 days ago
CVE-2026-12243-NLTK-PoC preview

CVE-2026-12243-NLTK-PoC

GitHubmorzelowski/cve-2026-12243-nltk-poc

Docker lab demonstrating CVE-2026-12243 path traversal in NLTK before 3.10.0, contrasting vulnerable and patched behavior with a synthetic secret in…

container-securityeducationlabs-practice+2
1 month ago
Previous12…14Next