Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
qubes-core-admin preview

qubes-core-admin

GitHubqubesos/qubes-core-admin

Manages the core lifecycle of Qubes OS domains via a Python admin API, handling secure compartmentalization with Xen and exposing an event system for…

defensive-toolssecurity-virtualizationutilities-frameworks
1472 days ago
cve-2026-85706 preview

cve-2026-85706

GitHubguneykabel/cve-2026-85706

Python PoC exploit for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE via Workhorse path-encoding bypass, with writeup and…

exploitationinformation-gatheringpenetration-testing+4
4214 days ago
CVE-2013-2028-Exploit preview

CVE-2013-2028-Exploit

GitHubvanivamshi/cve-2013-2028-exploit

Docker-based lab and Python exploit for CVE-2013-2028, an Nginx 1.3.9 chunked-parser integer overflow, covering canary recovery, mprotect, and…

binary-exploitationeducationexploitation+6
12 days ago
CVE-2025-64512_PoC preview

CVE-2025-64512_PoC

GitHubjinook-kim/cve-2025-64512_poc

Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

ctfeducationexploitation+5
10 days ago
CVE-2026-89274-wp-recipe-maker-poc preview

CVE-2026-89274-wp-recipe-maker-poc

GitHubhassham1/cve-2026-89274-wp-recipe-maker-poc

Docker validation lab and Python PoC for CVE-2026-89274, proving arbitrary shortcode execution in WP Recipe Maker <= 10.8.1 via rating-comment…

exploitationlabs-practicepenetration-testing+5
2 days ago
edk2 preview

edk2

GitHubtianocore/edk2

EDK II

cryptographyeducationembedded-systems-security+3
6.3k1 day ago
see preview

see

GitHubwithsecureopensource/see

Sandboxed Execution Environment

dynamic-analysis-sandboxingmalware-analysissecurity-virtualization
8215 years ago
minicps preview

minicps

GitHubscy-phy/minicps

Real-time simulation framework for cyber-physical systems with physical process/control device models and Mininet-based network emulation, built for…

network-securityscada-ics-securitysecurity-virtualization
1983 months ago
capsule preview

capsule

GitHubcapsulerun/capsule

Secure runtime to sandbox AI agent tasks. Run untrusted code in isolated WebAssembly environments.

ai-securitycloud-securitycontainer-security+5
2963 months ago
amla-sandbox preview

amla-sandbox

GitHubamlalabs/amla-sandbox

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

ai-securitycontainer-securitygeneral-purpose-utilities+2
3454 months ago
vpod preview

vpod

GitHubcapsulerun/vpod

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

ai-securitycontainer-securitydefensive-tools+3
744 days ago
ephemora-cell preview

ephemora-cell

GitHubmichaels1011/ephemora-cell

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

ai-securityapi-securitycloud-security+4
4450 minutes ago
csf preview

csf

GitHubarmourbird/csf

ArmourBird CSF - Container Security Framework

api-securitycloud-infrastructure-securityconfiguration-auditing+4
446 years ago
StepJack preview

StepJack

GitHubborealisai/stepjack

Benchmarking framework for evaluating computer-use AI agents against multi-step indirect prompt injection, with automatic adversarial goal…

adversarial-attackai-securitydynamic-analysis-sandboxing+2
54 months ago
Copy-Fail preview

Copy-Fail

GitHubphalanx-ccs/copy-fail

Passive diagnostic tool that checks if a Linux system is vulnerable to CVE-2026-31431 by testing AF_ALG socket reachability, providing mitigation…

exploitationpenetration-testingsecurity-virtualization+2
14 months ago
cve-2026-87902-poc preview

cve-2026-87902-poc

GitHubressl/cve-2026-87902-poc

PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned…

exploitationlabs-practicepenetration-testing+4
33 days ago
Win11Debloat preview

Win11Debloat

GitHubraphire/win11debloat

A simple, lightweight PowerShell script that allows you to remove pre-installed apps, disable telemetry, as well as perform various other changes to…

general-purpose-utilitiesprivacyscripting-automation+1
57.6k15 days ago
zeroboot preview

zeroboot

GitHubzerobootdev/zeroboot

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

ai-securitycloud-securitycontainer-security+3
2.5k6 months ago
Previous123Next