Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
bumblebee preview

bumblebee

GitHubperplexityai/bumblebee

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

devsecopsincident-responseinformation-gathering+3
5.0k
27 days ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

adversarial-attackai-securitycurated-resources+6
1.4k3 days ago
vulnerable-mcp-servers-lab preview

vulnerable-mcp-servers-lab

GitHubappsecco/vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

ai-securitycode-analysiseducation+7
2778 months ago
supply-chain-monitor preview

supply-chain-monitor

GitHubelastic/supply-chain-monitor

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

code-analysisincident-responsemalware-analysis+3
5315 months ago
CVE-2021-44228_scanner preview
Archived

CVE-2021-44228_scanner

GitHubcertcc/cve-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

code-analysisincident-responsestatic-analysis+3
3504 years ago
SupplyChainAttacks preview

SupplyChainAttacks

GitHubbinarly-io/supplychainattacks

Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

curated-resourceseducationfirmware-analysis+4
2831 year ago
mini-shai-hulud-scanner preview

mini-shai-hulud-scanner

GitHubintrudify/mini-shai-hulud-scanner

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

forensicsincident-responseioc-management+6
23 months ago
shai-scan preview

shai-scan

GitHubdigi4care/shai-scan

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

code-analysisdevsecopsincident-response+6
3 months ago
Reports preview

Reports

GitHubj4ck3lsyn-gen2/reports

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

binary-exploitationcurated-resourcesexploitation+8
21 month ago
tanstack-compromise-checker preview

tanstack-compromise-checker

GitHubry-allan/tanstack-compromise-checker

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

command-and-controlforensicsincident-response+6
3 months ago
solarwinds-sunburst-cve-2020-10148 preview

solarwinds-sunburst-cve-2020-10148

GitHubhorrister/solarwinds-sunburst-cve-2020-10148

Curated vulnerability writeups with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for real-world software…

cloud-securitydns-analysiseducation+6
12 months ago
scan-shai-hulud preview

scan-shai-hulud

GitHubqi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

forensicsincident-responseioc-management+6
13 months ago
notepadpp-supply-chain-iocs preview

notepadpp-supply-chain-iocs

GitHubrenat0z3r0/notepadpp-supply-chain-iocs

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

educationforensicsincident-response+6
16 months ago
Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094- preview

Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-

GitHubfevar54/detectar-backdoor-en-liblzma-de-xz-utils-cve-2024-3094-

Regla YARA para detectar el backdoor de liblzma en XZ Utils 5.6.0/5.6.1 (CVE-2024-3094).

incident-responseintrusion-detectionioc-management+3
2 years ago
CVE-2024-3094-XZ-Backdoor-Detector preview

CVE-2024-3094-XZ-Backdoor-Detector

GitHubdevjanger/cve-2024-3094-xz-backdoor-detector

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

forensicsincident-responsemalware-analysis+3
2 years ago
CVE-2021-44228-Advisories preview
Archived

CVE-2021-44228-Advisories

GitHubleetxyz/cve-2021-44228-advisories

List of company advisories log4j

curated-resourcesincident-responsesupply-chain-security+2
4 years ago
scavenger_scanner preview

scavenger_scanner

GitHubpaspke/scavenger_scanner

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

incident-responseioc-managementmalware-analysis+3
4 months ago
CVE-2021-44228-Log4Shell-Hashes preview

CVE-2021-44228-Log4Shell-Hashes

GitHubmubix/cve-2021-44228-log4shell-hashes

Hashes for vulnerable LOG4J versions

forensicsincident-responseioc-management+3
1554 years ago
Previous12Next