Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
456 results
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
781
4 months ago
android-check preview

android-check

GitHubnoveogroup/android-check

Static code analysis plugin for Android project. (Checkstyle, PMD)

android-securitycode-analysisdevsecops+1
2658 years ago
skillscript preview

skillscript

GitHubsshwarts/skillscript

Skillscript — a small declarative language for authoring agent workflows. Runtime, compiler, and CLI.

ai-securitydevsecopseducation+3
7414 days ago
dexfinder preview

dexfinder

GitHubjunelegency/dexfinder

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

android-securitybinary-analysiscode-analysis+6
1015 months ago
DevSec-Defense preview

DevSec-Defense

GitHubdanielbohannon/devsec-defense

Accompanying PowerShell Modules for DevSec Defense Presentation

defensive-toolsdevsecopseducation+1
318 years ago
sloppy-joe preview

sloppy-joe

GitHubbrennhill/sloppy-joe

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

code-analysisdevsecopseducation+5
325 months ago
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
313 months ago
cve-2025-59489 preview

cve-2025-59489

GitHubtaptap/cve-2025-59489

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

android-securitydevsecopsmobile-security+2
1510 months ago
bidi-guard preview

bidi-guard

GitHubmoshe-ship/bidi-guard

Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)

code-analysisdevsecopseducation+3
55 months ago
rsc-security-auditor preview

rsc-security-auditor

GitHubabdozkaya/rsc-security-auditor

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix…

code-analysisdevsecopseducation+3
59 months ago
CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline preview

CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline

GitHubgeorge0papasotiriou/cve-2026-11120-command-injection-via-git-url-in-ci-cd-pipeline

Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical…

devsecopseducationexploitation+1
1 month ago
Android-rce-analizi preview

Android-rce-analizi

GitHubbfurkanyildiz/android-rce-analizi

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamı

android-securityctfdevsecops+8
23 months ago
compromised-action preview

compromised-action

GitHubsuper-vulnerable-org/compromised-action

Test repo: simulates CVE-2025-30066 style compromised GitHub Action (for security research/testing chainradar)

devsecopseducationred-teaming+2
4 months ago
node-vulnerable preview

node-vulnerable

GitHubdannyendortest/node-vulnerable

Synthetic demo target for EXPOSURE — CVE-2018-21268 (traceroute) + CVE-2018-3757 (pdf-image)

code-analysisdevsecopseducation+3
3 months ago
log4j-vuln-demo preview

log4j-vuln-demo

GitHubaaronm-sysdig/log4j-vuln-demo

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

cloud-securitydevsecopseducation+3
3 months ago
Teach-AppSec preview

Teach-AppSec

GitHubowasp/teach-appsec

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

devsecopseducationlearning-paths-courses
2 months ago
vulnerable-java-app preview

vulnerable-java-app

GitHubbhimsekhar/vulnerable-java-app

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

devsecopseducationsupply-chain-security+3
3 months ago
ollama preview

ollama

GitHubdannyendortest/ollama

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…

devsecopseducationexploitation+3
3 months ago
Previous1…242526Next