Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
4430 results
Claude-BugHunter preview

Claude-BugHunter

GitHubelementalsouls/claude-bughunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

api-securitycloud-securitycurated-resources+8
3.7k
3h 53m ago
SkillSpector preview

SkillSpector

GitHubnvidia/skillspector

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

ai-securitycode-analysisdevsecops+8
14.9k13h 44m ago
intentshield preview

intentshield

GitHubmattijsmoens/intentshield

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

ai-securityanomaly-detectioncode-analysis+9
2014h 51m ago
sec-af preview

sec-af

GitHubagent-field/sec-af

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

ai-securitycode-analysisdevsecops+7
19419h 52m ago
Apkx-Hunter preview

Apkx-Hunter

GitHubsyscallx-18113/apkx-hunter

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

android-securityinformation-gatheringmachine-learning+7
8521h 37m ago
claude-bug-bounty preview

claude-bug-bounty

GitHubshuvonsec/claude-bug-bounty

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

ai-securitycloud-securityexploitation+8
4.3k1 day ago
CVE-2026-41089-Netlogon-RCE preview

CVE-2026-41089-Netlogon-RCE

GitHubopensource-arrozconpollo191/cve-2026-41089-netlogon-rce

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

educationexploitationpenetration-testing+2
11 day ago
cve-2025-66398 preview

cve-2025-66398

GitHubshowy-headteacher114/cve-2025-66398

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

exploitationpayload-developmentpenetration-testing+3
11 day ago
appsec-agent preview

appsec-agent

GitHubowasp/appsec-agent

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

ai-securitycode-analysisdevsecops+5
81 day ago
demo-cve-2022-22947 preview

demo-cve-2022-22947

GitHubentr0pie/demo-cve-2022-22947
code-analysisexploitationpenetration-testing+2
1 day ago
Anthropic-Cybersecurity-Skills preview

Anthropic-Cybersecurity-Skills

GitHubmukul975/anthropic-cybersecurity-skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3…

ai-securitycloud-securitycurated-resources+9
30.6k1 day ago
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.2k1 day ago
RegPwn preview

RegPwn

GitHubtracyliving606/regpwn

Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions

binary-exploitationexploitationpenetration-testing+4
32 days ago
CVE-2026-20841 preview

CVE-2026-20841

GitHubhamzamalik3461/cve-2026-20841

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

command-and-controlexploitationpayload-development+3
12 days ago
shannon preview

shannon

GitHubkeygraphhq/shannon

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

ai-securityapi-security-testingcode-analysis+5
47.0k2 days ago
PAYLOAD-LISTS preview

PAYLOAD-LISTS

GitHubnu11secur1ty/payload-lists
curated-resourceseducationpayload-generation+3
42 days ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubk3ystr0k3r/cve-2026-39987

Proof-of-concept exploit for Marimo pre-authentication RCE. Uses the unauthenticated /terminal/ws WebSocket endpoint to spawn a PTY and establish a…

exploitationpenetration-testingred-teaming+2
2 days ago
PyIris preview

PyIris

GitHubnot-sekiun/pyiris

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

command-and-controlexploitationpayload-generation+4
3272 days ago
Previous12…100Next