Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
55 results
heisenberg-ssc-gha preview

heisenberg-ssc-gha

GitHubappomni-labs/heisenberg-ssc-gha

GitHub Action for Heisenberg SSC

devsecopssecret-detectionsupply-chain-security+1
7
8 months ago
dumpscan preview
Archived

dumpscan

GitHubdaddycocoaman/dumpscan

Finding secrets in kernel and user memory

cryptographydigital-forensicsencryption-decryption-tools+4
1182 years ago
pyWhat preview

pyWhat

GitHubbee-san/pywhat

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

data-exfiltrationeducationforensics+7
7.3k3 years ago
shhgit preview

shhgit

GitHubeth0izzle/shhgit

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

code-analysisdevsecopsosint+2
4.0k1 year ago
tirith preview

tirith

GitHubsheeki03/tirith

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

curated-resourcesdata-exfiltrationdevsecops+8
2.7k7 days ago
shotlooter preview

shotlooter

GitHubutkusen/shotlooter

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc

data-exfiltrationinformation-gatheringosint+2
6481 year ago
nord-stream preview

nord-stream

GitHubsynacktiv/nord-stream

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

data-exfiltrationdevsecopsexploitation+5
3721 month ago
pillager preview

pillager

GitHubbrittonhayes/pillager

Pillage filesystems for sensitive information with Go 🔍

data-exfiltrationinformation-gatheringpenetration-testing+4
3138 months ago
golddigger preview

golddigger

GitHubustayready/golddigger

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

data-exfiltrationinformation-gatheringpenetration-testing+1
1983 years ago
agent-sweep preview

agent-sweep

GitHubishannaik/agent-sweep

Find and redact secrets in AI coding agent histories (Claude Code, and more).

data-exfiltrationdata-recoveryforensics+3
590 days ago
gitlab-watchman preview

gitlab-watchman

GitHubpapermtn/gitlab-watchman

Finding exposed secrets and personal data in GitLab

code-analysisdata-exfiltrationdevsecops+3
2061 year ago
Veritensor preview

Veritensor

GitHubarsbr/veritensor

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

ai-securitycode-analysisdata-exfiltration+8
8516 days ago
exfil-scan preview

exfil-scan

GitHubvikasudasi/exfil-scan

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

ai-securityapi-securitydata-exfiltration+2
626 days ago
ContextHound preview

ContextHound

GitHubiulianvostrut/contexthound

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

ai-securitycode-analysisdata-exfiltration+6
21 month ago
aigate preview

aigate

GitHubjricramc/aigate

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

ai-securityapi-securitycode-analysis+3
64 months ago
CVE-2025-10681 preview

CVE-2025-10681

GitHubmichaeladamgroberman/cve-2025-10681

CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

cloud-securitydata-exfiltrationembedded-systems-security+8
2 months ago
CVE-2025-14847_Expolit preview

CVE-2025-14847_Expolit

GitHubalexcyberx/cve-2025-14847_expolit
database-securitydata-exfiltrationexploitation+4
27 months ago
mongobleed preview

mongobleed

GitHubim-hanzou/mongobleed

CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure

database-securitydata-exfiltrationexploitation+3
7 months ago
Previous1234Next