Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
857 results
layne preview

layne

GitHubrocketchat/layne

A doggo that helps look for security issues in your repositories.

ai-securitycode-analysisdevsecops+4
122 months ago
synaptic-sentinel preview

synaptic-sentinel

GitHubgolab-arch/synaptic-sentinel

The vibe-coding security sentinel. Apache-2.0 agentic security toolkit for AI-assisted projects: 5 deterministic scouts + LLM Brain Layer (BYOK…

ai-securitycode-analysisdevsecops+6
62 months ago
vibegate preview

vibegate

GitHubthemiddleblue/vibegate

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

ai-securitycode-analysisdevsecops+5
82 months ago
AtomShields preview

AtomShields

GitHubelevenpaths/atomshields

Security testing framework for repositories and source code

code-analysisdevsecopsmisconfiguration+3
108 years ago
gha-lab-ca4fa82ac5 preview

gha-lab-ca4fa82ac5

GitHubpvharmo2/gha-lab-ca4fa82ac5

Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit…

curated-resourcesdevsecopseducation+3
12 days ago
evm-audit-helpers preview

evm-audit-helpers

GitLabdannydoodlesstory/evm-audit-helpers

Collection of Solidity snippets and Foundry scripts for smart contract security audits

code-analysiscurated-resourcesdevsecops+3
12 days ago
gha-lab-f894926966 preview

gha-lab-f894926966

GitHubpvharmo2/gha-lab-f894926966

Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer/dag-factory snapshot at 464c75a —…

curated-resourcesdevsecopseducation+2
13 days ago
bidi-guard preview

bidi-guard

GitHubmoshe-ship/bidi-guard

Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)

code-analysisdevsecopseducation+3
55 months ago
rsc-security-auditor preview

rsc-security-auditor

GitHubabdozkaya/rsc-security-auditor

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix…

code-analysisdevsecopseducation+3
59 months ago
miasma-toolkit preview

miasma-toolkit

GitHubjchable/miasma-toolkit

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

devsecopseducationforensics+7
2 months ago
nextjs-cve-2026-23870-checker preview

nextjs-cve-2026-23870-checker

GitHubemresandikci/nextjs-cve-2026-23870-checker

Checker and fixer for all 13 vulnerabilities in the Next.js May 2026 security release (CVE-2026-23870)

code-analysisdevsecopsmisconfiguration+3
14 months ago
seal-security-nuget-demo-net7 preview

seal-security-nuget-demo-net7

GitHubisecuritytw/seal-security-nuget-demo-net7

.NET 7 fork of seal-security-nuget-demo: same CVE-2024-21907 exploit story, retargeted for customers locked to .NET SDK 7.

curated-resourcesdevsecopseducation+2
4 months ago
node-vulnerable preview

node-vulnerable

GitHubdannyendortest/node-vulnerable

Synthetic demo target for EXPOSURE — CVE-2018-21268 (traceroute) + CVE-2018-3757 (pdf-image)

code-analysisdevsecopseducation+3
3 months ago
compromised-action preview

compromised-action

GitHubsuper-vulnerable-org/compromised-action

Test repo: simulates CVE-2025-30066 style compromised GitHub Action (for security research/testing chainradar)

devsecopseducationred-teaming+2
4 months ago
Checkmarx-CVE-2025-30066-Detection-Tool preview

Checkmarx-CVE-2025-30066-Detection-Tool

GitHubcheckmarx/checkmarx-cve-2025-30066-detection-tool

Scans GitHub workflows and logs for indicators of CVE-2025-30066, detecting malicious actions and exposed secrets using Checkmarx 2ms integration.

code-analysisdevsecopslog-analysis+3
11 year ago
ollama preview

ollama

GitHubdannyendortest/ollama

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…

devsecopseducationexploitation+3
3 months ago
invokeai preview

invokeai

GitHubdannyendortest/invokeai

Synthetic demo target for CVE-2024-10821 vulnerability detection and automated fix via compensating control. Demonstrates one-click PR-based…

devsecopseducationmisconfiguration+3
3 months ago
jenkinsci__workflow-cps-global-lib-plugin_CVE-2022-25174_544-vff04fa68714d preview

jenkinsci__workflow-cps-global-lib-plugin_CVE-2022-25174_544-vff04fa68714d

GitHubshoucheng3/jenkinsci__workflow-cps-global-lib-plugin_cve-2022-25174_544-vff04fa68714d

Exploit for CVE-2022-25174 in Jenkins Pipeline Shared Libraries plugin, demonstrating code injection via crafted library definitions for security…

code-analysisdevsecopseducation+2
1 year ago
Previous1…464748Next