Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
semgrep-rules preview

semgrep-rules

GitHubtrailofbits/semgrep-rules

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

code-analysisdevsecopsmisconfiguration+2
525
3 months ago
hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final preview

hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final

GitHubshoucheng3/hibernate__hibernate-validator_cve-2019-10219_6-0-17-final

Reference implementation of Bean Validation 2.0 (JSR-380) providing annotation-driven metadata model and API for JavaBean and method validation with…

api-securitycode-analysismisconfiguration+2
1 year ago
struts1filter preview

struts1filter

GitHubrgielen/struts1filter

A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team

code-analysisdevsecopsmisconfiguration+3
129 years ago
spring-web-without-remoting preview

spring-web-without-remoting

GitHubyihtserns/spring-web-without-remoting

Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027.

code-analysismisconfigurationstatic-analysis+2
2 years ago
springhound preview

springhound

GitHubmebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

code-analysismisconfigurationstatic-analysis+2
4 years ago
log4shell-finder preview

log4shell-finder

GitHubhynekpetrak/log4shell-finder

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305,…

code-analysismisconfigurationstatic-analysis+3
393 years ago
nahsra__antisamy_CVE-2017-14735_1-5-6 preview

nahsra__antisamy_CVE-2017-14735_1-5-6

GitHubshoucheng3/nahsra__antisamy_cve-2017-14735_1-5-6

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

api-securitycode-analysismisconfiguration+3
9 months ago
Magento-APSB22-48-Security-Patches preview

Magento-APSB22-48-Security-Patches

GitHubemicoecommerce/magento-apsb22-48-security-patches

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

code-analysismisconfigurationstatic-analysis+3
373 years ago
log4j-vulnerability-patcher-agent preview

log4j-vulnerability-patcher-agent

GitHubsaharnooby/log4j-vulnerability-patcher-agent

Fixes CVE-2021-44228 in log4j by patching JndiLookup class

code-analysisdevsecopsmisconfiguration+3
34 years ago
log4j-scanner preview

log4j-scanner

GitHubname/log4j-scanner

Discover Log4Shell vulnerability [CVE-2021-44832]

code-analysismisconfigurationstatic-analysis+3
12 years ago
log4j-scanner-CVE-2021-44228 preview

log4j-scanner-CVE-2021-44228

GitHubgeorge-petrakis/log4j-scanner-cve-2021-44228

Simple tool for scanning entire directories for attempts of CVE-2021-44228

code-analysismisconfigurationstatic-analysis+3
24 years ago
lblfixer_cve_2023_28447 preview

lblfixer_cve_2023_28447

GitHubdrkbcn/lblfixer_cve_2023_28447

Module for PrestaShop 1.7.X to fix CVE-2023-28447 vulnerability (Smarty XSS)

code-analysismisconfigurationstatic-analysis+2
23 years ago
jquery-prototype-pollution-fix preview

jquery-prototype-pollution-fix

GitHubbitnesswise/jquery-prototype-pollution-fix

A fix for CVE-2019-11358 (prototype pollution in jquery)

code-analysismisconfigurationstatic-analysis+2
67 years ago
sudowp-dropzone-elementor preview

sudowp-dropzone-elementor

GitHubsudo-wp/sudowp-dropzone-elementor

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

api-securitycode-analysismisconfiguration+3
5 months ago
log4shelldetect preview

log4shelldetect

GitHub1lann/log4shelldetect

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

code-analysismisconfigurationstatic-analysis+3
454 years ago
electronegativity preview

electronegativity

GitHubdoyensec/electronegativity

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

code-analysismisconfigurationstatic-analysis+1
1.1k1 year ago
bidi_char_detector preview
Archived

bidi_char_detector

GitHubmaweil/bidi_char_detector

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

code-analysismisconfigurationsecret-detection+3
63 years ago