Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
80 results
log4j-honeypot-flask preview

log4j-honeypot-flask

GitHubbinarydefense/log4j-honeypot-flask

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

defensive-toolsintrusion-detectionnetwork-security+2
149
4 years ago
xz-vulnerable-honeypot preview

xz-vulnerable-honeypot

GitHublockness-ko/xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

defensive-toolsincident-responsenetwork-security+2
1462 years ago
pki-toolbox preview

pki-toolbox

GitHubyoukyi/pki-toolbox

Client-side PKI toolbox that decodes X.509, CSR, chain, CRL, PKCS#7 and PKCS#12 artifacts, views ASN.1, converts formats, and generates self-signed…

cryptographydefensive-toolsencryption-decryption-tools+4
56 days ago
block-copyfail preview

block-copyfail

GitHubatgreen/block-copyfail

BPF LSM blocker for CVE-2026-31431 (Copy Fail) — blocks authencesn AF_ALG binds at runtime without rebooting

defensive-toolsdynamic-analysis-sandboxingincident-response+1
74 months ago
mirth-connect-security-poc preview

mirth-connect-security-poc

GitHubabhinavagarwal07/mirth-connect-security-poc

Working PoCs for three NextGen Connect 4.5.2 vulnerabilities.

defensive-toolseducationexploitation+4
18 days ago
CVE-2024-37054-PoC preview

CVE-2024-37054-PoC

GitHubclearlotus-git/cve-2024-37054-poc

Proof-of-concept and research repository for CVE-2024-37054, an unsafe deserialization flaw in MLflow PyFunc model loading that can lead to remote…

ai-securitydefensive-toolseducation+4
9 days ago
pocKeycloakCVE-2023-0264 preview

pocKeycloakCVE-2023-0264

GitHubeliangonzi00/pockeycloakcve-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

authenticationdefensive-toolsexploitation+7
2 months ago
cve-2026-22732-poc preview

cve-2026-22732-poc

GitHubdylan-chainguard/cve-2026-22732-poc

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

defensive-toolseducationexploitation+3
17 days ago
whale-sentinel-services preview

whale-sentinel-services

GitHubyangyang-research/whale-sentinel-services

The Whale Sentinel Services

anomaly-detectioncloud-securitydefensive-tools+3
11 year ago
cve-2024-32019-PoC preview

cve-2024-32019-PoC

GitHubayub0x7/cve-2024-32019-poc

Checks Netdata ndsudo SUID PATH privilege escalation exposure for CVE-2024-32019 and validates patches without weaponized exploitation.

defensive-toolsexploitationpenetration-testing+3
1 year ago
scan preview

scan

GitHubatomdrift-project/scan

0-day malware detection for binaries, source & scripts (that doesn't suck)

binary-analysiscode-analysisdefensive-tools+9
514 days ago
CVE-2026-57836-Confluent_Kafka preview

CVE-2026-57836-Confluent_Kafka

GitHubrahulreddykarne/cve-2026-57836-confluent_kafka

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

cloud-securitycryptographydefensive-tools+4
2 days ago
openedr preview

openedr

GitHubcomodosecurity/openedr

Open EDR public repository

defensive-toolsforensicsincident-response+2
2.7k4 months ago
cyberbro preview

cyberbro

GitHubstanfrbd/cyberbro

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

defensive-toolsdns-analysiseducation+9
6903 days ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4394 years ago
riotpot preview

riotpot

GitHubaau-network-security/riotpot

IoT and Operational Technology Honeypot

defensive-toolsinformation-gatheringiot-security+2
1053 years ago
fawkes preview

fawkes

GitHubgaloryber/fawkes

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

cloud-securitycommand-and-controlcontainer-escape+7
382 months ago
NGWAF preview

NGWAF

GitHubfa-pengfei/ngwaf

First iteration of ML based Feedback WAF

anomaly-detectiondefensive-toolseducation+7
603 years ago
Previous12345Next