Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
exfil-scan preview

exfil-scan

GitHubvikasudasi/exfil-scan

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

ai-securityapi-securitydata-exfiltration+2
6
29 days ago
jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1 preview

jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1

GitHubshoucheng3/jenkinsci__workflow-cps-plugin_cve-2022-25173_2646-v6ed3b5b01ff1
code-analysisdevsecopsdynamic-analysis-sandboxing+3
10 months ago
cve-2025-55182-mitigator preview

cve-2025-55182-mitigator

GitHubrashedhasan090/cve-2025-55182-mitigator
code-analysisdefensive-toolsdevsecops+3
8 months ago
keyhog preview

keyhog

GitHubsanthreal/keyhog

Open-source secret scanner in Rust

cloud-securitycode-analysisconfiguration-auditing+8
925h 32m ago
safe-chain preview

safe-chain

GitHubaikidosec/safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

defensive-toolsdevsecopsmalware-analysis+3
1.7k3 days ago
cve-2024-3094 preview

cve-2024-3094

GitHubfelipecosta09/cve-2024-3094

A tutorial on how to detect the CVE 2024-3094

cloud-securitycontainer-securitydevsecops+3
42 years ago
Log4j-Updater preview

Log4j-Updater

GitHubvinnimarcon/log4j-updater

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

configuration-auditingdevsecopsgeneral-purpose-utilities+3
24 years ago
zerobox preview

zerobox

GitHubafshinm/zerobox

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

ai-securitycontainer-securitydevsecops+1
7073 months ago
TraceTree preview

TraceTree

GitHubtejasprasad2008-afk/tracetree

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

container-securitydevsecopsdynamic-analysis-sandboxing+6
421 day ago
clawdstrike preview

clawdstrike

GitHubbackbay-labs/clawdstrike

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

ai-securitycloud-securitycontainer-security+5
2872 months ago
horusec preview

horusec

GitHubzupit/horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

cloud-securitycode-analysiscontainer-security+4
1.3k8 days ago
threatspec preview

threatspec

GitHubthreatspec/threatspec

threatspec - continuous threat modeling, through code

devsecopseducationthreat-intelligence+1
3915 years ago
DakshSCRA preview

DakshSCRA

GitHubcoffeeandsecurity/dakshscra
code-analysisdevsecopseducation+7
455 months ago
cicd-sensor preview

cicd-sensor

GitLabcicd-sensor/cicd-sensor

eBPF-powered runtime security sensor for CI/CD pipelines. Detects supply-chain attacks, logs process ancestry and file access, and provides forensic…

cloud-securitydevsecopsforensics+3
11 day ago