Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k
3 days ago
vUSBf preview

vUSBf

GitHubschumilo/vusbf

A QEMU/KVM-based USB fuzzing framework that finds device-driver bugs via reproducible VM execution, multiprocessing, and XML testcase generation.

dynamic-analysis-sandboxingfuzzinghardware-security+2
1709 years ago
kata-containers preview

kata-containers

GitHubkata-containers/kata-containers

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel…

cloud-infrastructure-securitycloud-securitycontainer-escape+4
8.7k57 minutes ago
metasploitable3 preview

metasploitable3

GitHubrapid7/metasploitable3

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

dynamic-analysis-sandboxingeducationexploit-frameworks+4
5.7k1 year ago
ScoutSuite preview

ScoutSuite

GitHubnccgroup/scoutsuite

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
7.8k2 years ago
vm2 preview

vm2

GitHubpatriksimek/vm2

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

code-analysisdynamic-analysis-sandboxingsecurity-virtualization+1
4.1k14h 51m ago
rex preview

rex

GitHubrex-rs/rex

Rex is a safe and usable kernel extension framework that allows loading and executing Rust kernel extension programs in the place of eBPF.

dynamic-analysis-sandboxingembedded-systems-securitysecurity-virtualization
5572 days ago
VMwareCloak preview

VMwareCloak

GitHubd4rksystem/vmwarecloak

A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.

defensive-toolsdynamic-analysis-sandboxingmalware-analysis+1
4481 year ago
HyperDeceit preview

HyperDeceit

GitHubxyrem/hyperdeceit

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

adversarial-attackbinary-analysisids-ips-evasion+3
3833 years ago
Securekit preview

Securekit

GitLabroxanne_ardary/securekit

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

ai-securityapi-securitycloud-security+5
1 month ago
CVE-2026-21636 preview

CVE-2026-21636

GitHubpauldechassey/cve-2026-21636

Proof-of-concept demonstrating a Node.js permission model bypass (CVE-2026-21636) that allows network access via undici/fetch to local services,…

container-securityexploitationpenetration-testing+3
4 months ago
sandbox-runtime preview

sandbox-runtime

GitHubanthropic-experimental/sandbox-runtime

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

configuration-auditingcontainer-securitydefensive-tools+4
5.1k21h 15m ago
DSP preview

DSP

GitHubdockersecurityplayground/dsp

A Microservices-based framework for the study of Network Security and Penetration Test techniques

container-securityeducationlabs-practice+3
6325 months ago
Zapscape preview

Zapscape

GitHubaarif450/zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

binary-exploitationdefensive-toolsexploitation+2
15 days ago
UserLAnd preview

UserLAnd

GitHubcypherpunkarmory/userland

Main UserLAnd Repository

general-purpose-utilitiessecurity-virtualization
4.3k8 days ago
Win11Debloat preview

Win11Debloat

GitHubraphire/win11debloat

A simple, lightweight PowerShell script that allows you to remove pre-installed apps, disable telemetry, as well as perform various other changes to…

general-purpose-utilitiesprivacyscripting-automation+1
56.5k4 days ago
gvisor preview

gvisor

GitHubgoogle/gvisor

Sandboxes containers via a userspace application kernel that intercepts system calls, limits host kernel access, and integrates with…

cloud-infrastructure-securitycloud-securitycontainer-escape+4
19.2k1 day ago
flare-vm preview

flare-vm

GitHubmandiant/flare-vm

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

binary-analysisdebuggersdigital-forensics+10
9.0k2 months ago
Previous123Next