Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
50 results
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
28.3k13h 47m ago
gitleaks preview

gitleaks

GitHubgitleaks/gitleaks

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

code-analysisdevsecopssecret-detection+3
29.7k2 months ago
ndaal_public_SBOM_Auditor preview

ndaal_public_SBOM_Auditor

GitLabvpierre/ndaal_public_sbom_auditor

Offline single-binary web app that ingests CycloneDX, SPDX and syft SBOMs, runs an ensemble of CVE scanners, enriches findings with EPSS, CISA-KEV…

configuration-auditingdefensive-toolsdevsecops+7
12 days ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

ai-securitycommand-and-controldata-exfiltration+7
3773 months ago
terrier preview

terrier

GitHubheroku/terrier

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

container-securityhash-analysissupply-chain-security+1
2274 months ago
modelaudit preview

modelaudit

GitHubpromptfoo/modelaudit

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

adversarial-attackai-securitydata-exfiltration+8
7622h 15m ago
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

code-analysisconfiguration-auditingdefensive-tools+4
91 year ago
log4j-finder preview

log4j-finder

GitHubfox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

code-analysisincident-responsestatic-analysis+3
4393 years ago
minisign preview

minisign

GitHubjedisct1/minisign

A dead simple tool to sign files and verify digital signatures.

cryptographydefensive-toolsencryption-decryption-tools+1
2.8k1 month ago
titus preview

titus

GitHubpraetorian-inc/titus

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

code-analysiscontainer-securitydevsecops+6
7072 days ago
git-crypt preview

git-crypt

GitHubagwa/git-crypt

Transparent file encryption in git

authentication-authorizationcryptographydata-exfiltration+3
9.9k8 years ago
log4jhound preview

log4jhound

GitHubmebibite/log4jhound

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

code-analysisdevsecopsstatic-analysis+2
4 years ago
wheelaudit preview

wheelaudit

GitHubkriskimmerle/wheelaudit

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

code-analysisconfiguration-auditingdevsecops+5
37 months ago
sage preview

sage

GitHubgendigitalinc/sage

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

ai-securitycode-analysisdefensive-tools+6
31019 days ago
CVE-2021-44228_scanner preview
Archived

CVE-2021-44228_scanner

GitHubcertcc/cve-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

code-analysisincident-responsestatic-analysis+3
3504 years ago
GuardModel preview

GuardModel

GitHubshivang0/guardmodel

GitHub Action that scans ML model files for malicious code and security vulnerabilities

ai-securitycode-analysisdevsecops+5
29 months ago
springhound preview

springhound

GitHubmebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

code-analysismisconfigurationstatic-analysis+2
4 years ago
pip-audit preview

pip-audit

GitHubpypa/pip-audit

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

devsecopssecret-detectionsupply-chain-security+1
1.4k10 days ago
Previous123Next