Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
500 results
sast-scan-action preview

sast-scan-action

GitHuboffensive360/sast-scan-action

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

api-security-testingcloud-securitycode-analysis+4
1 month ago
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

api-security-testingcloud-securitycode-analysis+3
1 month ago
pigeon preview

pigeon

GitHubpigeonlabshq/pigeon

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

ai-securityapi-securityauthentication-authorization+3
72 days ago
ephemora-cell preview

ephemora-cell

GitHubmichaels1011/ephemora-cell

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

ai-securityapi-securitycloud-security+4
115 days ago
gha-lab-ca4fa82ac5 preview

gha-lab-ca4fa82ac5

GitHubpvharmo2/gha-lab-ca4fa82ac5

Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit…

curated-resourcesdevsecopseducation+3
4 days ago
gha-lab-2f775f277c preview

gha-lab-2f775f277c

GitHubpvharmo2/gha-lab-2f775f277c

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

cloud-securitycurated-resourcesdevsecops+2
5 days ago
CVE-2026-0915-json-Patch.-V2.0 preview

CVE-2026-0915-json-Patch.-V2.0

GitHubterra-nova83/cve-2026-0915-json-patch.-v2.0

Provides a security patch for CVE-2026-0915, adding strict JSON schema validation, input sanitization, and rate limiting to prevent injection and DoS…

api-securitydevsecopsvulnerability-analysis+1
6 months ago
pwnproxy preview

pwnproxy

GitHubericmtzmtz/pwnproxy

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

ai-securityapi-security-testingcrawler+6
45 days ago
spring-cvss-check preview

spring-cvss-check

GitHubxiaoqimikko/spring-cvss-check

Scans Java artifacts and source for Spring/Tomcat CVEs, compares vendor vs NVD CVSS scores, verifies exploitability conditions, and checks if fix…

configuration-auditingdevsecopssupply-chain-security+2
7 days ago
gha-lab-40e23db109 preview

gha-lab-40e23db109

GitHubpvharmo2/gha-lab-40e23db109

Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in…

cloud-securitydevsecopseducation+2
7 days ago
seal-security-nuget-demo-net7 preview

seal-security-nuget-demo-net7

GitHubisecuritytw/seal-security-nuget-demo-net7

.NET 7 fork of seal-security-nuget-demo: same CVE-2024-21907 exploit story, retargeted for customers locked to .NET SDK 7.

curated-resourcesdevsecopseducation+2
3 months ago
copyfail-fix preview

copyfail-fix

GitHubpaulorlima9/copyfail-fix

Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
3 months ago
React2Shell-Scanner preview

React2Shell-Scanner

GitHubwi3memake/react2shell-scanner

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

api-security-testingdevsecopspenetration-testing+3
318 months ago
pyrite preview

pyrite

GitLabrenich/pyrite

Hardware-bound & Cloud-gated binary execution, cryptographic provenance, and anti-tamper envelope sealing for Crystal.

binary-analysiscloud-securitycryptography+3
210 days ago
copy-fail-CVE-2026-31431-mitigation-ansible-playbook preview

copy-fail-CVE-2026-31431-mitigation-ansible-playbook

GitHubmlazzarotto/copy-fail-cve-2026-31431-mitigation-ansible-playbook

An Ansible Playbook to mitigate the vulnerability CVE-2026-31431 on RHEL-based and Debian-based OSes.

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
4 months ago
ansible-role-cve-2026-31431 preview

ansible-role-cve-2026-31431

GitHubjoltcan/ansible-role-cve-2026-31431

Ansible role that applies and verifies the modprobe.d mitigation for CVE-2026-31431 by disabling the algif_aead kernel module, with safety checks for…

cloud-infrastructure-securityconfiguration-auditingdevsecops+1
4 months ago
cve-2026-31431-ansible preview

cve-2026-31431-ansible

GitHubaestechno/cve-2026-31431-ansible

Ansible playbook to detect and apply kernel cmdline mitigation for CVE-2026-31431 (Copy Fail) across Debian/Ubuntu/RHEL fleets, with read-only…

cloud-infrastructure-securityconfiguration-auditingdevsecops+1
34 months ago
cve-2026-0300-audit preview

cve-2026-0300-audit

GitHubtailwindrg/cve-2026-0300-audit

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

cloud-infrastructure-securityconfiguration-auditingdevsecops+3
4 months ago
Previous12…28Next