Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
OWASP-Subtractive-Hardening-Top-10 preview

OWASP-Subtractive-Hardening-Top-10

GitHubowasp/owasp-subtractive-hardening-top-10

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

ai-securitycloud-securitycontainer-security+6
21
1 day ago
DB_Audit_Research preview

DB_Audit_Research

GitHubmthamil107/db_audit_research

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

adversarial-attackdatabase-securitydefensive-tools+4
1 day ago
AI-Infra-Guard preview

AI-Infra-Guard

GitHubtencent/ai-infra-guard

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

ai-securitycloud-securitycontainer-security+7
4.9k1 day ago
hal preview

hal

GitHubemsec/hal

HAL – The Hardware Analyzer

binary-analysiseducationembedded-systems-security+6
8206 days ago
longfellow-zk preview

longfellow-zk

GitHubgoogle/longfellow-zk

Implementation of the Google Zero-Knowledge library for Identity Protocols.

authenticationcryptographyeducation+3
1.3k8 days ago
IAGA-Sentinel preview

IAGA-Sentinel

GitHubiaga-team/iaga-sentinel

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

ai-securitycontainer-securitycryptography+4
1798 days ago
chimera preview

chimera

GitHubpenberg/chimera

Sandbox untrusted code with safe access to the host.

binary-analysiscode-analysisdynamic-analysis-sandboxing+3
12512 days ago
HyperDbg preview

HyperDbg

GitHubhyperdbg/hyperdbg

State-of-the-art native debugging tools

binary-analysisdebuggerseducation+4
4.0k18 days ago
Dirty-Frag-Research-CVE-2026-43284- preview

Dirty-Frag-Research-CVE-2026-43284-

GitHubnabhan-mohy/dirty-frag-research-cve-2026-43284-

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

container-securityincident-responseintrusion-detection+2
20 days ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
623 days ago
Porting-CVE-2026-31431-Copy-Fail-to-a-Constrained-Java-Runner preview

Porting-CVE-2026-31431-Copy-Fail-to-a-Constrained-Java-Runner

GitHubkarollooool/porting-cve-2026-31431-copy-fail-to-a-constrained-java-runner

CVE-2026-31431 (copy.fail) — adapted for constrained Java execution environments via FFM syscall layer + javac annotation processor delivery

binary-exploitationcontainer-escapeeducation+7
125 days ago
Iran-War-Media preview

Iran-War-Media

GitHubalbintouma/iran-war-media

Iran War Media Monitor collects news articles covering the US-Israeli war on Iran and applies sentiment analysis to uncover who supports and opposes…

crawlereducationinformation-gathering+3
1927 days ago
CVE-2026-55994 preview

CVE-2026-55994

GitHuboscerd/cve-2026-55994

PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an…

code-analysiseducationexploitation+3
29 days ago
mcpguard-dynamic preview

mcpguard-dynamic

GitHubfacebook/mcpguard-dynamic

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

ai-securitycode-analysiscontainer-security+8
711 month ago
helm-plugin-path-traversal-security-assessment preview

helm-plugin-path-traversal-security-assessment

GitHubamnsecurity/helm-plugin-path-traversal-security-assessment

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

cloud-securitycontainer-securitycurated-resources+6
11 month ago
eternal preview

eternal

GitHubadriancable/eternal

Minimal machine architecture with LLVM compiler backend, Linux port, and virtual machine for creating self-contained software capsules that remain…

curated-resourceseducationhardware-security+3
2111 month ago
apache-activemq-rce-research preview

apache-activemq-rce-research

GitHubdinosn/apache-activemq-rce-research

Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison

educationexploitationpapers-research+4
81 month ago
container-escape-ebpf preview

container-escape-ebpf

GitHubscherepiuk/container-escape-ebpf

POCs and Tetragon Rules for CVE-2024-21626 and CVE-2025-31133

container-escapecontainer-securityeducation+3
11 month ago
Previous123Next