Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
93 results
SpeculativeExecutionAssessment preview

SpeculativeExecutionAssessment

GitHubgregaskew/speculativeexecutionassessment

Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754

cloud-securityconfiguration-auditinghardware-security+3
6 years ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
5834 days ago
edk2 preview

edk2

GitHubtianocore/edk2

EDK II

cryptographyeducationembedded-systems-security+3
6.2k6 days ago
obfus.h preview

obfus.h

GitHubdosx-dev/obfus.h

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

binary-analysiscode-analysisdefensive-tools+2
1.9k1 month ago
tamago preview

tamago

GitHubusbarmory/tamago

Framework for compiling and executing Go applications on bare metal processors, enabling secure firmware development with reduced attack surface…

embedded-systems-securityfirmware-analysishardware-security+1
2.0k12 days ago
clawk preview

clawk

GitHubclawkwork/clawk

Give coding agents a disposable Linux VM, not your laptop

cloud-securitycontainer-securitydevsecops+3
1.0k1 month ago
riscy-business preview

riscy-business

GitHubthesecretclub/riscy-business

RISC-V Virtual Machine

payload-developmentreverse-engineeringsecurity-virtualization
2981 year ago
amla-sandbox preview

amla-sandbox

GitHubamlalabs/amla-sandbox

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

ai-securitycontainer-securitygeneral-purpose-utilities+2
3464 months ago
block-copyfail preview

block-copyfail

GitHubmrunalp/block-copyfail

BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4

cloud-securitycontainer-securitydefensive-tools+2
14 months ago
agentbox preview

agentbox

GitHubsiyad01/agentbox

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

cloud-infrastructure-securitycontainer-securitydevsecops+3
14 months ago
Cordon preview
Archived

Cordon

GitHubvishnunandan555/cordon

Run any command inside a restricted filesystem view on Linux

configuration-auditingcontainer-securitydevsecops+6
24 months ago
SecGen preview

SecGen

GitHubcliffe/secgen

Create randomly insecure VMs

ctfeducationlabs-practice+3
2.8k17 days ago
Podroid preview

Podroid

GitHubextv/podroid

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

android-securitycontainer-securityhardware-iot-security+3
2.6k11 days ago
AndroSH preview

AndroSH

GitHubahmed-alnassif/androsh

AndroSH No-Root Multi-Distro Linux on Android via Shizuku/ADB - Run Arch, Fedora, Alpine, Debian, Ubuntu, Kali, Void, Manjaro, OpenSUSE & Chimera…

android-securitycontainer-securityeducation+6
2476 days ago
tandasat.github.io preview

tandasat.github.io

GitHubtandasat/tandasat.github.io

Remote hypervisor development class for security researchers; covers virtualization internals, hypervisor security, and vulnerabilities in privileged…

educationlearning-paths-coursesreverse-engineering+2
193 months ago
AgentCyTE preview

AgentCyTE

GitHubanantaakotal/agentcyte

Generates reproducible CORE network topologies from XML scenario files for cybersecurity training and experimentation. Provides Web GUI and CLI for…

educationlabs-practicenetwork-security+3
39 months ago
CVE-2026-53519 preview

CVE-2026-53519

GitHubivanesk315/cve-2026-53519

Docker lab reproducing CVE-2026-53519, a pre-auth path traversal in Nezha Dashboard that leaks jwt_secret_key and enables JWT forgery and admin…

authenticationeducationexploitation+5
5 days ago
cve-2026-22732-poc preview

cve-2026-22732-poc

GitHubdylan-chainguard/cve-2026-22732-poc

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

defensive-toolseducationexploitation+3
4 days ago
Previous123456Next