Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
157 results
gitleaks preview

gitleaks

GitHubgitleaks/gitleaks

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

code-analysisdevsecopssecret-detection+3
29.4k
1 month ago
checkov preview

checkov

GitHubbridgecrewio/checkov

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

cloud-infrastructure-securitycloud-securitycode-analysis+12
9.0k17h 27m ago
zizmor preview

zizmor

GitHubzizmorcore/zizmor

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

cloud-securitycode-analysisdevsecops+5
6.5k3 days ago
kube-linter preview

kube-linter

GitHubstackrox/kube-linter

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
3.5k16h 2m ago
packj preview

packj

GitHubossillate-inc/packj

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

devsecopsdynamic-analysis-sandboxingmalware-analysis+3
6931 day ago
flawfinder preview

flawfinder

GitHubdavid-a-wheeler/flawfinder

a static analysis tool for finding vulnerabilities in C/C++ source code

code-analysisdevsecopsstatic-analysis+2
5824 months ago
pybatfish preview

pybatfish

GitHubbatfish/pybatfish

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
2432 days ago
Bughound preview

Bughound

GitHubmhaskar/bughound

Static code analysis tool based on Elasticsearch

code-analysisdevsecopsstatic-code-analysis+2
1305 years ago
Veritensor preview

Veritensor

GitHubarsbr/veritensor

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

ai-securitycode-analysisdata-exfiltration+8
851 month ago
deepsecrets preview

deepsecrets

GitHubavito-tech/deepsecrets

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

code-analysisdevsecopssecret-detection+1
1932 years ago
malware-check preview

malware-check

GitHubmomenbasel/malware-check

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

binary-analysiscode-analysisdevsecops+7
644 months ago
TraceTree preview

TraceTree

GitHubtejasprasad2008-afk/tracetree

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

container-securitydevsecopsdynamic-analysis-sandboxing+6
422 days ago
DakshSCRA preview

DakshSCRA

GitHubcoffeeandsecurity/dakshscra

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

code-analysisdevsecopseducation+7
4525 days ago
ci-supplychain-guard preview

ci-supplychain-guard

GitHubotsmane-ahmed/ci-supplychain-guard

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

code-analysiscontainer-securitydevsecops+5
287 months ago
docf-sec-check preview

docf-sec-check

GitHubosmankandemir/docf-sec-check

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

code-analysisdevsecopsstatic-analysis+1
59 months ago
jeremylong__DependencyCheck_CVE-2018-12036_3-1-2 preview

jeremylong__DependencyCheck_CVE-2018-12036_3-1-2

GitHubshoucheng3/jeremylong__dependencycheck_cve-2018-12036_3-1-2

Software composition analysis tool that detects publicly disclosed vulnerabilities in project dependencies using CPE matching, generating detailed…

code-analysisdevsecopsstatic-analysis+3
1 year ago
gokart preview
Archived

gokart

GitHubpraetorian-inc/gokart

A static analysis tool for securing Go code

code-analysisdevsecopsmisconfiguration+3
2.2k2 years ago
ContextHound preview

ContextHound

GitHubiulianvostrut/contexthound

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

ai-securitycode-analysisdata-exfiltration+6
22 months ago
Previous12…9Next