Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
187 results
webauthn_tpm_portable preview

webauthn_tpm_portable

GitHubmimi89999/webauthn_tpm_portable

Portable, hardware-backed WebAuthn credentials using TPM 2.0. Deterministic parent key derived from a master seed enables cross-device credential…

authenticationcryptographyencryption-decryption-tools+2
4
6 months ago
Zapscape preview

Zapscape

GitHubaarif450/zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

binary-exploitationdefensive-toolsexploitation+2
13 days ago
AgentCyTE preview

AgentCyTE

GitHubanantaakotal/agentcyte

Generates reproducible CORE network topologies from XML scenario files for cybersecurity training and experimentation. Provides Web GUI and CLI for…

educationlabs-practicenetwork-security+3
39 months ago
aegisagent preview

aegisagent

GitHubhuzjie/aegisagent

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

ai-securityanomaly-detectionapi-security+4
1 month ago
Securekit preview

Securekit

GitLabroxanne_ardary/securekit

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

ai-securityapi-securitycloud-security+5
1 month ago
cve-2026-22732-poc preview

cve-2026-22732-poc

GitHubdylan-chainguard/cve-2026-22732-poc

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

defensive-toolseducationexploitation+3
8 days ago
Copy-Fail preview

Copy-Fail

GitHubphalanx-ccs/copy-fail

Passive diagnostic tool that checks if a Linux system is vulnerable to CVE-2026-31431 by testing AF_ALG socket reachability, providing mitigation…

exploitationpenetration-testingsecurity-virtualization+2
14 months ago
cve-2026-31431-mitigation preview

cve-2026-31431-mitigation

GitHublinux-zs/cve-2026-31431-mitigation

Seccomp-based mitigation for CVE-2026-31431, a Linux kernel LPE. Blocks AF_ALG socket via PAM module and standalone wrapper, with auto-detection of…

configuration-auditingdefensive-toolssecurity-virtualization+1
4 months ago
CUAHarm preview

CUAHarm

GitHubdb-ol/cuaharm

Benchmark for evaluating safety risks of computer-using agents, with 104 realistic misuse scenarios across seven malicious categories, supporting…

ai-securityeducationlabs-practice+3
111 months ago
CVE-2026-2441_PoC preview

CVE-2026-2441_PoC

GitHubatiilla/cve-2026-2441_poc

Proof-of-concept exploit for CVE-2026-2441, demonstrating the vulnerability and providing a working exploit for security testing and validation.

exploitationpenetration-testingsecurity-virtualization+2
6 months ago
external_libcap-Android10_r33_CVE-2023-2603 preview

external_libcap-Android10_r33_CVE-2023-2603

GitHubpazhanivelmani/external_libcap-android10_r33_cve-2023-2603

POSIX.1e capability library for Android 10, addressing CVE-2023-2603 with tools for setting and getting process capabilities to manage privilege…

android-securitybinary-analysisexploitation+3
1 year ago
Graylog2__graylog2-server_CVE-2023-41044_5-1-2 preview

Graylog2__graylog2-server_CVE-2023-41044_5-1-2

GitHubshoucheng3/graylog2__graylog2-server_cve-2023-41044_5-1-2

Open source log management platform for centralized log aggregation, real-time analysis, and security event monitoring with customizable dashboards…

anomaly-detectionincident-responseintrusion-detection+3
9 months ago
cve-2024-32019-PoC preview

cve-2024-32019-PoC

GitHubayub0x7/cve-2024-32019-poc

Checks Netdata ndsudo SUID PATH privilege escalation exposure for CVE-2024-32019 and validates patches without weaponized exploitation.

defensive-toolsexploitationpenetration-testing+3
1 year ago
FalconDash preview

FalconDash

GitHubfalconforceteam/falcondash

Azure workbook dashboard that visualizes and explores detection performance metrics, helping security teams measure and proactively maintain their…

cloud-securitydefensive-toolsincident-response+3
98 days ago
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

container-securitydevsecopsdns-subdomain-enumeration+8
17 days ago
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

ai-securityauthentication-authorizationcloud-security+7
8.6k4 days ago
ThreatIntel-Aggregator preview

ThreatIntel-Aggregator

GitHubethan-andrews/threatintel-aggregator

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs…

ai-securitydefensive-toolsincident-response+7
144 days ago
CVE-2026-27607 preview
Archived

CVE-2026-27607

GitHubnikeee/cve-2026-27607

Proof-of-concept exploit for CVE-2026-27607, a missing post-policy validation in RustFS, demonstrating the vulnerability with a Node.js script and…

exploitationpenetration-testingsecurity-virtualization+2
16 months ago
Previous1…456…11Next