Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
Boucle-framework preview

Boucle-framework

GitHubbande-a-bonnot/boucle-framework

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

ai-securityconfiguration-auditingdata-exfiltration+3
124
11h 37m ago
nuguard preview

nuguard

GitHubnuguardai/nuguard

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

ai-securityapi-security-testingcode-analysis+8
5017h 27m ago
CVE-2026-86259 preview

CVE-2026-86259

GitHubuziii2208/cve-2026-86259

OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

api-securitycloud-securitydata-exfiltration+6
9 days ago
CVE-2026-78122-POC preview

CVE-2026-78122-POC

GitHublegendile7/cve-2026-78122-poc

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…

configuration-auditingcontainer-securitydata-exfiltration+3
11 month ago
CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read preview

CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read

GitHubgeorge0papasotiriou/cve-2026-21015-php-filter-chain-arbitrary-file-read

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

data-exfiltrationexploitationinformation-gathering+4
1 month ago
CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting preview

CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting

GitHubgeorge0papasotiriou/cve-2026-21004-sqlite-fts3-match-infoleak-via-query-crafting

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

database-securitydata-exfiltrationexploitation+1
1 month ago
CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata preview

CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata

GitHubgeorge0papasotiriou/cve-2026-3333-dns-rebinding-to-steal-cloud-metadata

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

cloud-securitydata-exfiltrationexploitation+4
1 month ago
PrivateSphare preview

PrivateSphare

GitLabdshamany/privatesphare

An at-rest encrypted filesharing application with multiple clients who seek to share privately, without tracking.

cloud-securitydata-exfiltrationencryption-decryption-tools+1
2 months ago
GC2-sheet preview

GC2-sheet

GitHubloociprian/gc2-sheet

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

command-and-controldata-exfiltrationmalware-analysis+2
6543 months ago
pwnlift preview

pwnlift

GitHubrasta-mouse/pwnlift

Easy peasy file uploads

data-exfiltrationpenetration-testingremote-access-tool+2
423 months ago
token-proxy preview

token-proxy

GitHubzolderio/token-proxy

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

ai-securityapi-securitycloud-security+6
285 months ago
enseal preview

enseal

GitHubfleralex/enseal

Secure, ephemeral secret sharing for developers.

authenticationcloud-securityconfiguration-auditing+6
56 months ago
DeadManSwitch preview

DeadManSwitch

GitHubblacksnufkin/deadmanswitch

DeadManSwitch in rust with several triggers (remote local and network)

data-exfiltrationdefensive-toolsencryption-decryption-tools+4
2710 months ago
sqlwinds preview

sqlwinds

GitHubblue0x1/sqlwinds

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

configuration-auditingdatabase-securitydata-exfiltration+7
1 year ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubbhanunamikaze/cve-2024-42009

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

data-exfiltrationeducationexploitation+5
11 year ago
gitlab-watchman preview

gitlab-watchman

GitHubpapermtn/gitlab-watchman

Finding exposed secrets and personal data in GitLab

code-analysisdata-exfiltrationdevsecops+3
2071 year ago
kodex preview

kodex

GitHubkiprotect/kodex

A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data:…

configuration-auditingdata-exfiltrationdevsecops+3
1292 years ago
Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment preview

Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment

GitHubtadash10/exploiting-cve-2021-44228-log4shell-in-a-banking-environment

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

command-and-controldata-exfiltrationeducation+8
32 years ago
Previous12Next