Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
TS_LLMLib preview

TS_LLMLib

GitHubtrustedsec/ts_llmlib
ai-securitybinary-analysiscode-analysis+7
12 months ago
jenkinsci__git-client-plugin_CVE-2019-10392_2-8-4 preview

jenkinsci__git-client-plugin_CVE-2019-10392_2-8-4

GitHubshoucheng3/jenkinsci__git-client-plugin_cve-2019-10392_2-8-4
authenticationcode-analysisdevsecops+2
1 year ago
fix-react2shell-next preview

fix-react2shell-next

GitHubvercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

code-analysisdevsecopsscripting-automation+3
4018 months ago
react-vuln-scanner preview

react-vuln-scanner

GitHubumairahmadh/react-vuln-scanner

A bash script to scan your server for React applications vulnerable to **CVE-2025-55182** — a critical remote code execution vulnerability (CVSS…

code-analysisdevsecopsexploitation+3
8 months ago
React2Shell-CVE-2025-55182-Detector preview

React2Shell-CVE-2025-55182-Detector

GitHubgarethmsheldon/react2shell-cve-2025-55182-detector
code-analysisscripting-automationsupply-chain-security+3
18 months ago
detect-log4j-exploitable preview

detect-log4j-exploitable

GitHubm0rath/detect-log4j-exploitable

CVE-2021-44228

code-analysisexploitationscripting-automation+2
4 years ago
gobee preview

gobee

GitHubboratanrikulu/gobee

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

binary-analysiscode-analysisdevsecops+3
3463 months ago
mcp-stdio-shellguard preview

mcp-stdio-shellguard

GitHubstudiomeyer-io/mcp-stdio-shellguard

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

api-securitycode-analysisdevsecops+5
2 months ago
JSONPath preview

JSONPath

GitHubjsonpath-plus/jsonpath

A fork of JSONPath from http://goessner.net/articles/JsonPath/

code-analysisgeneral-purpose-utilitiesscripting-automation+2
1.2k10h 25m ago
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
3925 days ago
yaraast preview

yaraast

GitHubseifreed/yaraast

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

code-analysismalware-analysisscripting-automation+3
541 month ago
safe-expr-eval preview

safe-expr-eval

GitHubalecasg555/safe-expr-eval

Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability

code-analysisgeneral-purpose-utilitiesscripting-automation
42 months ago
DiffCatcher preview

DiffCatcher

GitHubteycir/diffcatcher

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

code-analysisdevsecopsinformation-gathering+7
44 months ago
agentwatch preview

agentwatch

GitHubfarjadahmed/agentwatch

Silent session recorder for Claude Code that logs every action, flags dangerous commands (rm -rf, sudo, curl|sh), and provides timeline review, risk…

forensicsincident-responselog-analysis+2
125 months ago
ai-code-review preview

ai-code-review

GitHubjaydendancer12/ai-code-review

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

ai-securitycode-analysisdevsecops+5
36 months ago