Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
40 results
ZSC preview

ZSC

GitHubowasp/zsc

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

encryption-decryption-toolsexploit-frameworkspayload-generation+5
6532 years ago
LLM-MCP-Security-Field-Guide preview

LLM-MCP-Security-Field-Guide

GitHubpathakabhi24/llm-mcp-security-field-guide

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

ai-securitycurated-resourceseducation+7
45 months ago
CVE-2026-16764 preview

CVE-2026-16764

GitHubhakaioffsec/cve-2026-16764

Python exploit for CVE-2026-16764, a privilege escalation in OWASP DefectDojo where an is_staff REST API bypass lets a low-privileged user gain…

api-securityauthentication-authorizationeducation+6
113 days ago
awesome-cybersec preview

awesome-cybersec

GitHubdhotrey/awesome-cybersec

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

ctfcurated-resourceseducation+8
1942 months ago
Basileak preview

Basileak

GitHubowasp/basileak

Intentionally vulnerable LLM

ai-securityctfeducation+6
321 month ago
CVE-2022-23808 preview

CVE-2022-23808

GitHubdipakpanchal05/cve-2022-23808

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

exploitationpenetration-testingred-teaming+3
1151 year ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
flareprox preview

flareprox

GitHubmrturvey/flareprox

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

api-security-testinginformation-gatheringpenetration-testing+5
79511 months ago
CVE-2023-27532 preview

CVE-2023-27532

GitHubhorizon3ai/cve-2023-27532

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

api-security-testingexploitationpenetration-testing+2
753 years ago
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

api-security-testingexploitationmisconfiguration+4
1 month ago
CVE-2020-23839 preview

CVE-2020-23839

GitHubboku7/cve-2020-23839

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

exploitationpayload-developmentpenetration-testing+3
125 years ago
RedTeamToolkit preview

RedTeamToolkit

GitHubowasp/redteamtoolkit

The WASM Based Security Toolkit for the Web First Paradigm

exploit-frameworksinformation-gatheringpenetration-testing-frameworks+3
386 years ago
agent-opfor preview

agent-opfor

GitHubkeyvaluesoftwaresystems/agent-opfor

Open-source adversary emulation for AI agents and MCP servers.

adversarial-attackai-securityapi-security-testing+5
5821 month ago
crucible preview

crucible

GitHubcrucible-security/crucible

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

ai-securitydevsecopseducation+3
502 months ago
oasis preview

oasis

GitHubkryptsec/oasis

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

ai-securityctfeducation+6
2913 days ago
llm-agent-testbed preview

llm-agent-testbed

GitHubpie-script/llm-agent-testbed

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

ai-securityapi-securityeducation+4
1624 days ago
DVAP preview

DVAP

GitHubsonuoffsec/dvap

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

ai-securityctfeducation+4
293 months ago
fas-judgement-oss preview

fas-judgement-oss

GitHubfallen-angel-systems/fas-judgement-oss

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

adversarial-attackai-securityctf+8
136 months ago
Previous123Next