Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
948 results
Agent-Security-Regression-Harness preview

Agent-Security-Regression-Harness

GitHubowasp/agent-security-regression-harness

Executable security regression testing for agentic applications and MCP-integrated systems.

ai-securityapi-security-testingcode-analysis+4
49
1 month ago
HoneyWire preview

HoneyWire

GitHubandreicscs/honeywire

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

container-securitydevsecopsincident-response+3
1033 days ago
skillscript preview

skillscript

GitHubsshwarts/skillscript

Skillscript — a small declarative language for authoring agent workflows. Runtime, compiler, and CLI.

ai-securitydevsecopseducation+3
7412 days ago
OpenClawMachines preview

OpenClawMachines

GitHubmathaix/openclawmachines

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

ai-securityauthenticationcloud-security+6
571 month ago
scodescanner preview

scodescanner

GitHubagrawalsmart7/scodescanner

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

code-analysisdevsecopsstatic-code-analysis+1
1623 years ago
preflight preview

preflight

GitHubpreflightsh/preflight

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

code-analysisconfiguration-auditingdevsecops+8
595 days ago
sqlsure preview

sqlsure

GitHubsqlsure/sqlsure

Semantic inspector for SQL — catches fan-out double-counting, additivity violations, wrong join keys, and policy breaches before the query runs.…

code-analysiscurated-resourcesdatabase-security+5
981 month ago
ccs preview

ccs

GitHubnccgroup/ccs

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…

code-analysisdevsecopssecret-detection+2
1143 years ago
threatmap preview

threatmap

GitHubbogdanticu88/threatmap

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

api-securitycloud-securityconfiguration-auditing+5
612 months ago
dexfinder preview

dexfinder

GitHubjunelegency/dexfinder

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

android-securitybinary-analysiscode-analysis+6
944 months ago
combobulator preview

combobulator

GitHubapiiro/combobulator

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

code-analysisdevsecopssupply-chain-security+1
952 years ago
Argus preview

Argus

GitHubpurs3lab/argus

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

code-analysisdevsecopseducation+4
542 years ago
agent-bom preview

agent-bom

GitHubmsaad00/agent-bom

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

ai-securitycloud-securitycontainer-security+6
313 days ago
threat-finder preview

threat-finder

GitHuboffseq/threat-finder

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

devsecopsnetwork-securitythreat-intelligence+2
574 days ago
DEFCON-CICD-pipelines-workshop preview

DEFCON-CICD-pipelines-workshop

GitHubwavestone-cdt/defcon-cicd-pipelines-workshop

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

cloud-securitycontainer-escapecontainer-security+8
933 years ago
faraday_agent_dispatcher preview

faraday_agent_dispatcher

GitHubinfobyte/faraday_agent_dispatcher

Faraday Agent Dispatcher launches any security tools and send results to Faradaysec Platform.

cloud-securitydevsecopsinformation-gathering+5
497 months ago
gh-safe-repo preview

gh-safe-repo

GitHubariesq/gh-safe-repo

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

cloud-securityconfiguration-auditingdevsecops+4
379 days ago
api-security-audit-action preview

api-security-audit-action

GitHub42crunch/api-security-audit-action

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

api-securityapi-security-testingdefensive-tools+3
3619 days ago
Previous1…111213…53Next