Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
GateX preview

GateX

GitHubabraxas/gatex

FortinetHunter (@YogSoth0) binary cracking application. Part of CTF for FortinetHunter. ELF door: a stripped Nuitka onefile, an XOR-scrambled…

binary-analysisbinary-exploitationcryptography+8
1
1 month ago
Cusimanse preview

Cusimanse

GitHubopposum0112/cusimanse

Composable research-contract and YAML-recipe framework for agent-operated security experiments on disposable compute

ai-securitydefensive-toolsdynamic-analysis-sandboxing+9
20 days ago
Decretum preview

Decretum

GitHubopposum0112/decretum

Contract LinkML compiler for a security researchers

configuration-auditingdefensive-toolsdigital-forensics+7
4 days ago
CVE-2026-15911-Confluent_Kafka preview

CVE-2026-15911-Confluent_Kafka

GitHubrahulreddykarne/cve-2026-15911-confluent_kafka

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

cloud-securitycryptographydefensive-tools+4
3 days ago
CVE-2026-102971 preview

CVE-2026-102971

GitHubbombobombone/cve-2026-102971

Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs.

exploitationinformation-gatheringpapers-research+3
7 days ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
17 days ago
Red-Team-GOAD-Lab-Proxmox preview

Red-Team-GOAD-Lab-Proxmox

GitHubpho5nix/red-team-goad-lab-proxmox

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

adversarial-attackcommand-and-controldefensive-tools+7
4711 days ago
CVE-2026-61500 preview

CVE-2026-61500

GitHubaramosf/cve-2026-61500

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

cryptographyeducationexploitation+7
11 days ago
CVE-2026-52782 preview

CVE-2026-52782

GitHubabraxas/cve-2026-52782

Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive…

exploitationinformation-gatheringlabs-practice+5
7 days ago
cplt preview

cplt

GitHubnavikt/cplt

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

ai-securitycommand-and-controlconfiguration-auditing+7
1281 day ago
DROS-VEP-lite preview

DROS-VEP-lite

GitHubtop-celestial-company-ltd/dros-vep-lite

Open-source, 100% reproducible AI Agent Runtime Security Benchmark & Sandbox Environment (RFC-010 Draft Protocol).

ai-securitydefensive-toolsdynamic-analysis-sandboxing+8
122 days ago
blackarch preview

blackarch

GitHubblackarch/blackarch

An ArchLinux based distribution for penetration testers and security researchers.

curated-resourceseducationexploit-frameworks+8
3.5k3 days ago
pentoo-overlay preview

pentoo-overlay

GitHubpentoo/pentoo-overlay

Gentoo overlay for security tools as well as the heart of the Pentoo Livecd

defensive-toolsexploit-frameworkshardware-security+7
3841 day ago
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

container-securitydevsecopsdns-subdomain-enumeration+8
13 days ago
ThreatIntel-Aggregator preview

ThreatIntel-Aggregator

GitHubethan-andrews/threatintel-aggregator

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs…

ai-securitydefensive-toolsincident-response+7
5922 days ago
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

ai-securityauthentication-authorizationcloud-security+7
15.3k4h 15m ago
CVE-2026-76461-Detection-Kit- preview

CVE-2026-76461-Detection-Kit-

GitHubfevar54/cve-2026-76461-detection-kit-

Defensive detection kit for CVE-2026-76461, a critical SQL injection in Cisco Secure Email Gateway, with Sigma and YARA rules, IOCs, and remediation…

defensive-toolsemail-securityincident-response+6
22 days ago
CVE-2026-82329-PoC-Exploit preview

CVE-2026-82329-PoC-Exploit

GitHubtc4dy/cve-2026-82329-poc-exploit

Exploit and detection toolkit for CVE-2026-82329, a JFrog Artifactory auth bypass. Forges join JWTs to mint admin tokens; includes a non-intrusive…

authenticationdefensive-toolsexploitation+7
322 days ago
Previous1234Next