Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
119 results
pybatfish preview

pybatfish

GitHubbatfish/pybatfish

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
243
5 days ago
zerobox preview

zerobox

GitHubafshinm/zerobox

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

ai-securitycontainer-securitydevsecops+1
7163 months ago
Boucle-framework preview

Boucle-framework

GitHubbande-a-bonnot/boucle-framework

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

ai-securityconfiguration-auditingdata-exfiltration+3
12410h 51m ago
autoSource preview

autoSource

GitHubshubhamshubhankar/autosource

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

code-analysisdevsecopsstatic-code-analysis+1
707 years ago
OpenClawMachines preview

OpenClawMachines

GitHubmathaix/openclawmachines

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

ai-securityauthenticationcloud-security+6
571 month ago
combobulator preview

combobulator

GitHubapiiro/combobulator

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

code-analysisdevsecopssupply-chain-security+1
952 years ago
threat-finder preview

threat-finder

GitHuboffseq/threat-finder

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

devsecopsnetwork-securitythreat-intelligence+2
5811 days ago
log4j2_vul_local_scanner preview

log4j2_vul_local_scanner

GitHublijiejie/log4j2_vul_local_scanner

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

code-analysiscontainer-securitydevsecops+3
854 years ago
vexhub preview

vexhub

GitHubaquasecurity/vexhub

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

devsecopsinformation-gatheringsupply-chain-security+2
395 months ago
react2shell-scanner preview

react2shell-scanner

GitHubgensecaihq/react2shell-scanner

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

code-analysiscontainer-securitydevsecops+4
589 months ago
test-certs-site preview

test-certs-site

GitHubletsencrypt/test-certs-site

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

api-security-testingdevsecopsencryption-decryption-tools+1
253 months ago
CVE-2024-3094-Vulnerability-Checker-Fixer preview

CVE-2024-3094-Vulnerability-Checker-Fixer

GitHubgensecaihq/cve-2024-3094-vulnerability-checker-fixer

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

cloud-securitydevsecopsmisconfiguration+3
262 years ago
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
303 months ago
sentinel-cve preview

sentinel-cve

GitHubkamalsrini/sentinel-cve

CLI tool that explains CVEs in plain English and scans repos for impact. Powered by Claude.

cloud-securitycontainer-securitydevsecops+6
206 months ago
proxmox-lxc-docker-fix preview

proxmox-lxc-docker-fix

GitHubjq6l43d1/proxmox-lxc-docker-fix

Workaround for CVE-2025-52881: Fixes Docker/Podman breakage in Proxmox LXC containers caused by AppArmor incompatibility with runc 1.2.7+. Universal…

cloud-infrastructure-securitycontainer-securitydevsecops+3
149 months ago
ansible-role-log4shell preview

ansible-role-log4shell

GitHubclaranet/ansible-role-log4shell

Ansible role to detect Log4Shell (CVE-2021-44228) by scanning filesystem and open files for vulnerable JAR/WAR files, reporting version and…

cloud-securityconfiguration-auditingdevsecops+2
112 years ago
rewrite-cve-2026-22732 preview

rewrite-cve-2026-22732

GitHubmoderneinc/rewrite-cve-2026-22732

OpenRewrite recipe that detects and fixes Spring Security header suppression (CVE-2026-22732) by identifying Content-Length header misuse and…

code-analysisdevsecopsstatic-analysis+2
4 days ago
Fern Pattern Scanner preview

Fern Pattern Scanner

GitLabgitlab-da/tutorials/security-and-governance/custom-scanner-integration/fern-pattern-scanner

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

code-analysisdevsecopseducation+3
52 years ago
Previous1234567Next