Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
279 results
BurpIA preview

BurpIA

GitHubdragonjar/burpia

Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.

ai-securityapi-security-testingdefensive-tools+7
18
1 month ago
QuickAssist_UAC_Bypass preview

QuickAssist_UAC_Bypass

GitHubr41n3rzuf477/quickassist_uac_bypass

UAC bypass PoC abusing the UIAccess QuickAssist binary to load an attacker-controlled DLL via WebView2 BrowserExecutableFolder, then hijack elevated…

defensive-toolsexploitationpayload-development+4
2412 months ago
bromite preview

bromite

GitHubbromite/bromite

Android Chromium fork with built-in ad blocking, anti-fingerprinting mitigations, DNS-over-HTTPS, and hardened privacy and security defaults.

android-securityanti-botdefensive-tools+7
6.3k2 years ago
Vanadium preview

Vanadium

GitHubgrapheneos/vanadium

Privacy and security hardened Chromium build providing the WebView and default browser for GrapheneOS, with OS-level hardening and compatibility…

android-securitydefensive-toolsgeneral-purpose-utilities+4
2.2k6 days ago
APEX_official preview

APEX_official

GitHubzhengxr930/apex_official

Defender framework for LLM agent security that compiles task contracts, validates capability manifests, and checks effects via PLANT/WRAP proof…

ai-assisted-reversingai-securityauthentication-authorization+5
5 days ago
detecttrace preview

detecttrace

GitHubg0dse11/detecttrace

Open-source detection engineering tool that traces security detections end to end and identifies the first failing stage.

defensive-toolsdevsecopsincident-response+5
15 days ago
ActiveScanPlusPlus preview

ActiveScanPlusPlus

GitHubalbinowax/activescanplusplus

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, expression language injection, shellshock and…

api-security-testingdefensive-toolsexploitation+7
66719 days ago
burp-ResponseClusterer preview

burp-ResponseClusterer

GitHubmodzero/burp-responseclusterer

Burp plugin that clusters responses to show an overview of received responses

anomaly-detectiondefensive-toolspenetration-testing+5
147 years ago
active-scan-plus-plus preview

active-scan-plus-plus

GitHubportswigger/active-scan-plus-plus

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, code injection, and known CVEs like…

api-security-testingdefensive-toolspenetration-testing+6
2572 months ago
ruby-saml preview

ruby-saml

GitHubsaml-toolkits/ruby-saml

Ruby library implementing the SAML Service Provider side of SSO, handling authn requests, response validation, XML signature checks, and IdP metadata…

authenticationauthentication-authorizationcryptography+4
9831 month ago
pyrasp preview

pyrasp

GitHubrbidou/pyrasp

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks…

ai-securityanomaly-detectionapi-security+6
397 days ago
waf-fu preview

waf-fu

GitHubconfused-binary/waf-fu

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

cloud-securitydefensive-toolsincident-response+6
21 month ago
CVE-2026-15911-Confluent_Kafka preview

CVE-2026-15911-Confluent_Kafka

GitHubrahulreddykarne/cve-2026-15911-confluent_kafka

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

cloud-securitycryptographydefensive-tools+4
6 days ago
CVE-2026-103752-Authorizer-Privilege-Escalation preview

CVE-2026-103752-Authorizer-Privilege-Escalation

GitHubanoxhunterdump-ctrl/cve-2026-103752-authorizer-privilege-escalation

Defensive analysis, patch breakdown, and passive detection scanner for CVE-2026-103752 (WordPress Authorizer Plugin <= 3.15.3).

defensive-toolsincident-responsepenetration-testing+3
8 days ago
ultrafuzz preview

ultrafuzz

GitHubmonad-developers/ultrafuzz

End-to-end agentic smart contract fuzzing and threat hunting

ai-securitydefensive-toolsfuzzing+5
982 days ago
CVE-2026-14378-DevKit-Pro-Auth-Bypass preview

CVE-2026-14378-DevKit-Pro-Auth-Bypass

GitHubanoxhunterdump-ctrl/cve-2026-14378-devkit-pro-auth-bypass

Defensive analysis, patch breakdown, and detection scanner for CVE-2026-14378 (WordPress DevKit Pro Plugin <= 2.3.0).

authenticationdefensive-toolsexploitation+5
8 days ago
quipu preview

quipu

GitHubcorelight/quipu

A desktop workbench for writing, validating, compiling, and testing YARA rules.

code-analysisdefensive-toolsdigital-forensics+6
116h 55m ago
CVE-2026-93616-check preview

CVE-2026-93616-check

GitHubbishopfox/cve-2026-93616-check

Safe unauthenticated patch-state checker for Check Point CPM RCE CVE-2026-93616; probes the UpgradeSvcRemote SOAP login on TCP 19009 without…

defensive-toolsexploitationnetwork-security+4
9 days ago
Previous12…16Next