Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
pyrocms-ssti-fix preview

pyrocms-ssti-fix

GitHubysaxon/pyrocms-ssti-fix

A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation

code-analysisdefensive-toolsmisconfiguration+3
8 months ago
nahsra__antisamy_CVE-2016-10006_1-5-3 preview

nahsra__antisamy_CVE-2016-10006_1-5-3

GitHubshoucheng3/nahsra__antisamy_cve-2016-10006_1-5-3

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

api-securitycode-analysisdefensive-tools+2
1 year ago
Zimbra-CVE-2017-8802-Hotifx preview

Zimbra-CVE-2017-8802-Hotifx

GitHubozzi-/zimbra-cve-2017-8802-hotifx

Security hotfix for CVE-2017-8802

defensive-toolsemail-securitymisconfiguration+2
8 years ago
Follina-Remediation preview
Archived

Follina-Remediation

GitHubcosmo121/follina-remediation

Removes the ability for MSDT to run, in response to CVE-2022-30190 (Follina)

defensive-toolsexploitationincident-response+2
43 years ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4071 year ago
SECURITY-3430 preview

SECURITY-3430

GitHubjenkinsci-cert/security-3430

Java agent that transforms a vulnerable class to block exploitation of CVE-2024-43044 in Jenkins controllers, with optional forced shutdown on…

code-analysisdefensive-toolsexploitation+2
22 years ago
mcp-doorman preview

mcp-doorman

GitHubsushank05/mcp-doorman

A lightweight mcp to prevent poisoning CVE (CVE-2025-54136), researchers hijacking Claude Code/Copilot/Gemini via prompt injection, and hundreds of…

ai-securityapi-securitydefensive-tools+5
4 days ago
java-html-sanitizer preview

java-html-sanitizer

GitHubowasp/java-html-sanitizer

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

api-securitycode-analysisdefensive-tools+3
9505 months ago
honeyslop preview

honeyslop

GitHubgadievron/honeyslop

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

code-analysisdefensive-toolseducation+6
983 months ago
Ghost-CMS-Code-Injection-Audit-CVE-2026-26980 preview

Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

GitHubkulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

code-analysisdefensive-toolsincident-response+3
16 days ago
DB_Audit_Research preview

DB_Audit_Research

GitHubmthamil107/db_audit_research

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

adversarial-attackdatabase-securitydefensive-tools+4
17 days ago
anti-jndi preview

anti-jndi

GitHubph0lk3r/anti-jndi

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

defensive-toolsids-ips-evasionmisconfiguration+3
24 years ago
mitigate-folina preview

mitigate-folina

GitHubderco0n/mitigate-folina

Mitigates the "Folina"-ZeroDay (CVE-2022-30190)

defensive-toolsincident-responsemisconfiguration+1
14 years ago
metasploitable-penetration-testing-lab preview

metasploitable-penetration-testing-lab

GitHubyagnikkrish/metasploitable-penetration-testing-lab

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

defensive-toolseducationexploitation+8
6 months ago
Spring4Shell-Python-Firewall-POC preview

Spring4Shell-Python-Firewall-POC

GitHubnickops87/spring4shell-python-firewall-poc

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

code-analysisdefensive-toolseducation+3
10 months ago
CVE-2022-41040_Mitigation preview

CVE-2022-41040_Mitigation

GitHubcentariscyber/cve-2022-41040_mitigation

PowerShell script to mitigate CVE-2022-41040 on affected Exchange servers by applying recommended configuration changes.

defensive-toolsexploitationmisconfiguration+2
3 years ago
LogJackFix preview

LogJackFix

GitHubponeyclairdelune/logjackfix

A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.

defensive-toolsexploitationincident-response+3
4 years ago
Log4j-CVE-2021-44228-Remediation preview

Log4j-CVE-2021-44228-Remediation

GitHubdigital-dev/log4j-cve-2021-44228-remediation

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…

cloud-securitydefensive-toolsincident-response+3
2 years ago
Previous123Next