Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
check-spelling preview

check-spelling

GitHubcheck-spelling/check-spelling

Spelling checker action to check spelling in repositories / pull requests / commits

code-analysisdevsecopseducation+2
333
5 months ago
threatspec preview

threatspec

GitHubthreatspec/threatspec

threatspec - continuous threat modeling, through code

devsecopseducationthreat-intelligence+1
3895 years ago
studio preview

studio

GitHubshipsecai/studio

Workflow automation for Security Teams

cloud-securitydevsecopseducation+7
3797 months ago
nuclei-templates-labs preview

nuclei-templates-labs

GitHubprojectdiscovery/nuclei-templates-labs

Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀

ctfcurated-resourcesdevsecops+8
1331 year ago
crucible preview

crucible

GitHubcrucible-security/crucible

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

ai-securitydevsecopseducation+3
502 months ago
sast-rules preview

sast-rules

GitLabgitlab-org/security-products/sast-rules

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

code-analysisdevsecopseducation+2
3014 days ago
Argus preview

Argus

GitHubpurs3lab/argus

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

code-analysisdevsecopseducation+4
552 years ago
skillscript preview

skillscript

GitHubsshwarts/skillscript

Skillscript — a small declarative language for authoring agent workflows. Runtime, compiler, and CLI.

ai-securitydevsecopseducation+3
751 month ago
DakshSCRA preview

DakshSCRA

GitHubcoffeeandsecurity/dakshscra

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

code-analysisdevsecopseducation+7
459 days ago
DevSec-Defense preview

DevSec-Defense

GitHubdanielbohannon/devsec-defense

Accompanying PowerShell Modules for DevSec Defense Presentation

defensive-toolsdevsecopseducation+1
318 years ago
SecuSphere preview

SecuSphere

GitHubsecurityuniversalorg/secusphere

Centralized DevSecOps platform for vulnerability management, CI/CD security integration, automated security assessment aggregation, and fostering…

devsecopseducationvulnerability-scanners
471 year ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1825 days ago
sloppy-joe preview

sloppy-joe

GitHubbrennhill/sloppy-joe

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

code-analysisdevsecopseducation+5
325 months ago
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
304 months ago
OreNPMGuard preview

OreNPMGuard

GitHubrapticore/orenpmguard

Defense Against the Shai-Hulud Supply Chain Attack

code-analysisdevsecopseducation+6
139 months ago
ore-mal-pkg-inspector preview

ore-mal-pkg-inspector

GitHubrapticore/ore-mal-pkg-inspector

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

code-analysisdevsecopseducation+6
84 months ago
CVE-2026-0303 preview

CVE-2026-0303

GitHubyonliud/cve-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

code-analysisdevsecopseducation+5
25 days ago
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

code-analysisdevsecopseducation+4
21 days ago
Previous1234Next