Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
456 results
check_struts preview

check_struts

GitHubandypitcher/check_struts

Apache Struts version analyzer (Ansible) based on CVE-2017-5638

cloud-securityconfiguration-auditingdevsecops+3
2
7 years ago
flight-risk preview

flight-risk

GitHubjoaoreis13/flight-risk

Security toolkit for CVE-2025-55182 (React2Shell) — scan, detect, correlate, and test React Server Components RCE vulnerability

cloud-securitycontainer-securitydevsecops+6
4 months ago
cve-2026-0300-audit preview

cve-2026-0300-audit

GitHubtailwindrg/cve-2026-0300-audit

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

cloud-infrastructure-securityconfiguration-auditingdevsecops+3
4 months ago
nginx-cve-fix preview

nginx-cve-fix

GitHubbarappteam/nginx-cve-fix

Source-built nginx 1.25.5 container with backported CVE-2026-42945 fix, OpenSSL bump, full provenance chain, and VEX attestation.

configuration-auditingcontainer-securitydevsecops+3
3 months ago
agentbox preview

agentbox

GitHubsiyad01/agentbox

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

cloud-infrastructure-securitycontainer-securitydevsecops+3
14 months ago
dasel-melange-apko preview

dasel-melange-apko

GitHubrotavori/dasel-melange-apko

dasel v3.3.1 packaged with Melange and shipped as a minimal apko image, patched for CVE-2026-33320

container-securitydevsecopsgeneral-purpose-utilities+3
3 months ago
docker-socket-risk-demos preview

docker-socket-risk-demos

GitHubashleyt3/docker-socket-risk-demos

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

cloud-infrastructure-securitycontainer-securitydevsecops+3
5 months ago
Patch-management- preview

Patch-management-

GitHubsalman-sec/patch-management-

Scenario-based training exercise for IT administrators: identify, approve, and deploy critical patches for financial systems under a 48-hour SLA…

cloud-securityconfiguration-auditingdevsecops+3
4 months ago
apache__dolphinscheduler_CVE-2023-51770_3_2_1_fixed preview

apache__dolphinscheduler_CVE-2023-51770_3_2_1_fixed

GitHubshoucheng3/apache__dolphinscheduler_cve-2023-51770_3_2_1_fixed

Exploit for CVE-2023-51770 targeting Apache DolphinScheduler versions 3.2.1 and earlier, enabling remote code execution via crafted workflow…

cloud-securitycontainer-securitydevsecops+3
1 year ago
go-dbmigrate preview

go-dbmigrate

GitHubmoisei-dev/go-dbmigrate

Go library and CLI for managing database schema migrations with support for PostgreSQL, MySQL, SQLite, and Cassandra, including up/down migration…

configuration-auditingdatabase-securitydevsecops+2
5 months ago
TriSuElla-AIDLCA-Framework preview

TriSuElla-AIDLCA-Framework

GitHubowasp/trisuella-aidlca-framework

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

ai-securitycloud-securitycode-analysis+7
12 days ago
Cordon preview
Archived

Cordon

GitHubvishnunandan555/cordon

Run any command inside a restricted filesystem view on Linux

configuration-auditingcontainer-securitydevsecops+6
24 months ago
vulnreport preview
Archived

vulnreport

GitHubsalesforce/vulnreport

Open-source pentesting management and automation platform by Salesforce Product Security

devsecopspenetration-testingpenetration-testing-frameworks+2
6004 years ago
Mobile-Security-Framework-MobSF preview

Mobile-Security-Framework-MobSF

GitHubmobsf/mobile-security-framework-mobsf

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

android-securityapi-security-testingdevsecops+8
21.8k24 days ago
PentestingEverything preview

PentestingEverything

GitHubm14r41/pentestingeverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

api-securitycloud-securityctf+9
2.1k2 days ago
terragoat preview

terragoat

GitHubbridgecrewio/terragoat

Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.

cloud-securitydevsecopseducation+2
1.3k3 years ago
CodeAnalysis preview

CodeAnalysis

GitHubtencent/codeanalysis

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

code-analysisdevsecopseducation+3
1.8k10 months ago
cicd-goat preview

cicd-goat

GitHubcider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

ctfdevsecopseducation+3
2.3k2 years ago
Previous1…23242526Next