Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
141 results
salus preview

salus

GitHubcoinbase/salus

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

code-analysisdevsecopssecret-detection+2
31
1 year ago
SecureAI-Scan preview

SecureAI-Scan

GitHubakanthed/secureai-scan

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

ai-securitycode-analysisdevsecops+5
1912 days ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.1k1 day ago
preflight preview

preflight

GitHubpreflightsh/preflight

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

code-analysisconfiguration-auditingdevsecops+8
5918h 5m ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
53326 days ago
ci-supplychain-guard preview

ci-supplychain-guard

GitHubotsmane-ahmed/ci-supplychain-guard

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

code-analysiscontainer-securitydevsecops+5
286 months ago
vulnhawk preview

vulnhawk

GitHubmomenbasel/vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

ai-securityapi-security-testingcloud-security+8
832 months ago
secretlint preview

secretlint

GitHubsecretlint/secretlint

Pluggable linting tool to prevent committing credential.

code-analysisdevsecopssecret-detection+1
1.4k4 days ago
Veritensor preview

Veritensor

GitHubarsbr/veritensor

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

ai-securitycode-analysisdata-exfiltration+8
851 month ago
ContextHound preview

ContextHound

GitHubiulianvostrut/contexthound

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

ai-securitycode-analysisdata-exfiltration+6
22 months ago
medusa preview

medusa

GitHubpantheon-security/medusa

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

ai-securitycloud-securitycode-analysis+8
97328 days ago
GuardScan preview

GuardScan

GitHubntanwir10/guardscan

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

ai-securityapi-securitycloud-security+8
152 months ago
GitLeaks preview

GitLeaks

GitLabniclas-zone/ctr/gitleaks

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

code-analysiscontainer-securitydevsecops+1
1 month ago
noseyparker preview
Archived

noseyparker

GitHubpraetorian-inc/noseyparker

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

code-analysisdevsecopsinformation-gathering+3
2.3k6 months ago
gokart preview
Archived

gokart

GitHubpraetorian-inc/gokart

A static analysis tool for securing Go code

code-analysisdevsecopsmisconfiguration+3
2.2k2 years ago
scanner-cli preview
Archived

scanner-cli

GitHubhawkeyesec/scanner-cli

A project security/vulnerability/risk scanning tool

code-analysiscontainer-securitydevsecops+3
3615 years ago
jsluice preview

jsluice

GitHubbishopfox/jsluice

Extract URLs, paths, secrets, and other interesting bits from JavaScript

code-analysisinformation-gatheringpenetration-testing+3
1.9k2 years ago
apm preview

apm

GitHubaaravmaloo/apm

A local password manager for everyone

authenticationcloud-securitycryptography+7
2921 days ago
Previous123…8Next