Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
27.5k
8h 30m ago
defenseclaw preview

defenseclaw

GitHubcisco-ai-defense/defenseclaw

Security Governance for Agentic AI

ai-securitycloud-securitycode-analysis+7
8221 day ago
supply-chain-monitor preview

supply-chain-monitor

GitHubelastic/supply-chain-monitor
code-analysisincident-responsemalware-analysis+3
5304 months ago
nah preview

nah

GitHubmanuelschipper/nah

a guard that blocks catastrophic agent actions

ai-securitycode-analysiscommand-and-control+8
4737 days ago
log4j-finder preview

log4j-finder

GitHubfox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

code-analysisincident-responsestatic-analysis+3
4393 years ago
CVE-2021-44228_scanner preview
Archived

CVE-2021-44228_scanner

GitHubcertcc/cve-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

code-analysisincident-responsestatic-analysis+3
3504 years ago
log4j_checker_beta preview

log4j_checker_beta

GitHubrubo77/log4j_checker_beta

a fast check, if your server could be vulnerable to CVE-2021-44228

code-analysisdynamic-analysis-sandboxingincident-response+3
2474 years ago
halogen preview
Archived

halogen

GitHubtarget/halogen

Automatically create YARA rules from malicious documents.

forensicsincident-responsemalware-analysis+2
2104 years ago
Reversecore_MCP preview

Reversecore_MCP

GitHubsjkim1127/reversecore_mcp

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

binary-analysisdigital-forensicsdynamic-analysis-sandboxing+7
1883 days ago
honeyslop preview

honeyslop

GitHubgadievron/honeyslop

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

code-analysisdefensive-toolseducation+6
973 months ago
keyhog preview

keyhog

GitHubsanthreal/keyhog

Open-source secret scanner in Rust

cloud-securitycode-analysisconfiguration-auditing+8
902 days ago
OffsetInspect preview

OffsetInspect

GitHubwarpedatom/offsetinspect

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

binary-analysisdefensive-toolsexploitation+8
8324 days ago
PolinRider preview

PolinRider

GitHubopensourcemalware/polinrider

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

code-analysiscurated-resourceseducation+8
801 month ago
mcpguard-dynamic preview

mcpguard-dynamic

GitHubfacebook/mcpguard-dynamic

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

ai-securitycode-analysiscontainer-security+8
711 month ago
Log4JShell-Bytecode-Detector preview

Log4JShell-Bytecode-Detector

GitHubcodeshield-security/log4jshell-bytecode-detector

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)

binary-analysiscode-analysisincident-response+3
494 years ago
jvmxray preview

jvmxray

GitHubspoofzu/jvmxray

Externalize Java application access to protected resources as log messages.

code-analysisdynamic-analysis-sandboxingincident-response+1
461 month ago
blmvuln preview

blmvuln

GitHubmathiasreker/blmvuln

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

code-analysisincident-responsemalware-analysis+3
424 years ago
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
3925 days ago
Previous12Next