Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
690 results
seal-security-nuget-demo-net7 preview

seal-security-nuget-demo-net7

GitHubisecuritytw/seal-security-nuget-demo-net7

.NET 7 fork of seal-security-nuget-demo: same CVE-2024-21907 exploit story, retargeted for customers locked to .NET SDK 7.

curated-resourcesdevsecopseducation+2
3 months ago
gha-lab-232af4821f preview

gha-lab-232af4821f

GitHubpvharmo2/gha-lab-232af4821f

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in…

devsecopseducationsupply-chain-security+1
1 day ago
copyfail-fix preview

copyfail-fix

GitHubpaulorlima9/copyfail-fix

Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
3 months ago
React2Shell-Scanner preview

React2Shell-Scanner

GitHubwi3memake/react2shell-scanner

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

api-security-testingdevsecopspenetration-testing+3
318 months ago
rewrite-cve-2026-22732 preview

rewrite-cve-2026-22732

GitHubmoderneinc/rewrite-cve-2026-22732

OpenRewrite recipe that detects and fixes Spring Security header suppression (CVE-2026-22732) by identifying Content-Length header misuse and…

code-analysisdevsecopsstatic-analysis+2
4 days ago
pyrite preview

pyrite

GitLabrenich/pyrite

Hardware-bound & Cloud-gated binary execution, cryptographic provenance, and anti-tamper envelope sealing for Crystal.

binary-analysiscloud-securitycryptography+3
5 days ago
Apache-CVE-2026-23918-fix preview

Apache-CVE-2026-23918-fix

GitHubrshosting/apache-cve-2026-23918-fix

Upgrade to Apache 2.4.67 to fix CVE-2026-23918 vulneribility

configuration-auditingdevsecopsvulnerability-analysis+1
3 months ago
copy-fail-CVE-2026-31431-mitigation-ansible-playbook preview

copy-fail-CVE-2026-31431-mitigation-ansible-playbook

GitHubmlazzarotto/copy-fail-cve-2026-31431-mitigation-ansible-playbook

An Ansible Playbook to mitigate the vulnerability CVE-2026-31431 on RHEL-based and Debian-based OSes.

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
4 months ago
copyfail-mitigation preview

copyfail-mitigation

GitHubmahradbt/copyfail-mitigation

Ansible playbooks to audit and mitigate CVE-2026-31431 ("Copy Fail"), a local privilege escalation vulnerability in the Linux kernel's `algif_aead`…

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
24 months ago
CVE-2026-31431-mitigation-suite preview

CVE-2026-31431-mitigation-suite

GitHubmahdi13830510/cve-2026-31431-mitigation-suite

Kernel-runtime defense framework for AF_ALG vulnerabilities, featuring eBPF socket tracing, Ansible hardening, and a crypto auditor for drift…

anomaly-detectioncloud-infrastructure-securityconfiguration-auditing+4
44 months ago
cve-2026-41940-scanner preview

cve-2026-41940-scanner

GitHublinko-iheb/cve-2026-41940-scanner

Passive, read-only vulnerability scanner for detecting CVE-2026-41940 in cPanel & WHM. Performs version-based fingerprinting, generates…

cloud-infrastructure-securityconfiguration-auditingdefensive-tools+3
14 months ago
ansible-role-cve-2026-31431 preview

ansible-role-cve-2026-31431

GitHubjoltcan/ansible-role-cve-2026-31431

Ansible role that applies and verifies the modprobe.d mitigation for CVE-2026-31431 by disabling the algif_aead kernel module, with safety checks for…

cloud-infrastructure-securityconfiguration-auditingdevsecops+1
3 months ago
copyfail-check preview

copyfail-check

GitHubcodesource/copyfail-check

Shell script to detect CVE-2026-31431 (Copy Fail) exposure and mitigations on Linux systems: kernel check, module state, boot params, AF_ALG…

configuration-auditingdevsecopsincident-response+2
24 months ago
cve-2026-0300-audit preview

cve-2026-0300-audit

GitHubtailwindrg/cve-2026-0300-audit

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

cloud-infrastructure-securityconfiguration-auditingdevsecops+3
3 months ago
cPanel-Fix preview

cPanel-Fix

GitHubmrarianet/cpanel-fix

One security-remediation.sh for CVE-2026-41940 (cPanel), CVE-2026-31431 (kernel "Copy Fail"), CSF, optional domain/proxy cleanup, and optional…

cloud-infrastructure-securityconfiguration-auditingdevsecops+3
14 months ago
audit-axios preview

audit-axios

GitHubsurri/audit-axios

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

code-analysisconfiguration-auditingdevsecops+3
4 months ago
agentbox preview

agentbox

GitHubsiyad01/agentbox

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

cloud-infrastructure-securitycontainer-securitydevsecops+3
3 months ago
kafka-keycloak-oauth preview

kafka-keycloak-oauth

GitHuboriolrius/kafka-keycloak-oauth

Apache Kafka 4.1.0 (KRaft) with Keycloak OAuth2 authentication using Strimzi - bypasses CVE-2025-27817 URL allowlist restriction

authenticationcloud-infrastructure-securityconfiguration-auditing+3
510 months ago
Previous12…39Next