Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
trivy preview

trivy

GitHubaquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

cloud-securitycode-analysiscontainer-security+5
37.5k
1 day ago
osv-scanner preview

osv-scanner

GitHubgoogle/osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

code-analysiscontainer-securitydevsecops+4
10.9k1 day ago
checkov preview

checkov

GitHubbridgecrewio/checkov

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

cloud-securitycode-analysiscontainer-security+6
9.0k8h 12m ago
SecretScanner preview

SecretScanner

GitHubdeepfence/secretscanner

:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

container-securitydevsecopssecret-detection+1
3.4k5 months ago
veinmind-tools preview

veinmind-tools

GitHubchaitin/veinmind-tools

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

cloud-securitycontainer-escapecontainer-security+7
1.7k2 years ago
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k3 days ago
trivy-action preview

trivy-action

GitHubaquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

cloud-securitycode-analysiscontainer-security+5
1.4k6 days ago
horusec preview

horusec

GitHubzupit/horusec

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

cloud-securitycode-analysiscontainer-security+4
1.3k6 days ago
titus preview

titus

GitHubpraetorian-inc/titus

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

code-analysiscontainer-securitydevsecops+6
67518 days ago
matchlock preview

matchlock

GitHubjingkaihe/matchlock

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

ai-securityapi-securitycloud-security+5
61226 days ago
pmg preview

pmg

GitHubsafedep/pmg

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

cloud-securitycontainer-securitydevsecops+6
4941 day ago
scanner-cli preview
Archived

scanner-cli

GitHubhawkeyesec/scanner-cli

A project security/vulnerability/risk scanning tool

code-analysiscontainer-securitydevsecops+3
3614 years ago
prismor preview

prismor

GitHubprismorsec/prismor

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

ai-securitycontainer-securitydefensive-tools+5
32412h 40m ago
bromure preview

bromure

GitHubrderaison/bromure

Proper sandboxing for agentic coding and web browsing

ai-securitycontainer-securitydynamic-analysis-sandboxing+6
2752 days ago
DockerSpy preview

DockerSpy

GitHubundeadsec/dockerspy

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

container-securityinformation-gatheringosint+1
2472 years ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

ai-securitycloud-securitycommand-and-control+7
20919h 55m ago
cynative preview

cynative

GitHubcynative/cynative

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

ai-securitycloud-securitycontainer-security+7
19116h 28m ago
pii-shield preview

pii-shield

GitHubpii-shield/pii-shield

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

cloud-securitycontainer-securitydata-exfiltration+4
16315h 17m ago
Previous12Next