Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
371 results
jsecret preview

jsecret

GitHubraoufmaklouf/jsecret

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

code-analysisinformation-gatheringsecret-detection+2
42
2 years ago
sops preview

sops

GitHubgetsops/sops

Simple and flexible tool for managing secrets

cloud-securityconfiguration-auditingcryptography+6
23.1k1 day ago
ElectricEye preview

ElectricEye

GitHubjonrau1/electriceye

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

cloud-securityconfiguration-auditingdevsecops+5
1.0k1 year ago
cred_scanner preview

cred_scanner

GitHubdisruptops/cred_scanner

A simple file-based scanner to look for potential AWS access and secret keys in files

cloud-securitycode-analysisdevsecops+1
948 years ago
keeper preview

keeper

GitHubagberohq/keeper

Simple Secure Keeper for Secrets

authentication-authorizationcryptographyencryption-decryption-tools+1
1235 months ago
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
313 months ago
CVE-2023-27587-PoC preview

CVE-2023-27587-PoC

GitHubvagnerd/cve-2023-27587-poc

The simple PoC of CVE-2023-27587

api-securityexploitationinformation-gathering+3
53 years ago
golddigger preview

golddigger

GitHubustayready/golddigger

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

data-exfiltrationinformation-gatheringpenetration-testing+1
1983 years ago
pillager preview

pillager

GitHubbrittonhayes/pillager

Pillage filesystems for sensitive information with Go 🔍

data-exfiltrationinformation-gatheringpenetration-testing+4
3169 months ago
CanaryHunter preview

CanaryHunter

GitHubc0axx/canaryhunter

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

adversarial-attackcloud-infrastructure-securityconfiguration-auditing+4
1373 years ago
sharemylogin preview

sharemylogin

GitHubelandio-com/sharemylogin

Zero-Knowledge Credential Sharing

authenticationencryption-decryption-toolsprivacy+3
571 month ago
agentic-dm-gateway preview

agentic-dm-gateway

GitLabwattocyber/agentic-dm-gateway

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to…

ai-securityauthentication-authorizationdata-exfiltration+2
18 days ago
mongobleed preview

mongobleed

GitHubim-hanzou/mongobleed

CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure

database-securitydata-exfiltrationexploitation+3
8 months ago
nah preview

nah

GitHubmanuelschipper/nah

a guard that blocks catastrophic agent actions

ai-securitycode-analysiscommand-and-control+8
4801 day ago
smokedmeat preview

smokedmeat

GitHubboostsecurityio/smokedmeat

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

cloud-securitycommand-and-controleducation+9
3771 month ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

ai-securitycloud-securitycommand-and-control+7
21011h 15m ago
SkillsGuard preview

SkillsGuard

GitHubteycir/skillsguard

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

ai-securitycode-analysiscommand-and-control+8
152 months ago
API-Security-Checklist preview

API-Security-Checklist

GitHubshieldfy/api-security-checklist

Checklist of the most important security countermeasures when designing, testing, and releasing your API

api-securityauthentication-authorizationcurated-resources+4
23.3k1 month ago
Previous12…21Next