Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
80 results
cli preview

cli

GitHubsnyk/cli

Snyk CLI scans and monitors your projects for security vulnerabilities.

cloud-infrastructure-securitycode-analysiscontainer-security+6
5.7k1 day ago
ci-supplychain-guard preview

ci-supplychain-guard

GitHubotsmane-ahmed/ci-supplychain-guard

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

code-analysiscontainer-securitydevsecops+5
287 months ago
agent-scan preview

agent-scan

GitHubsnyk/agent-scan

Security scanner for AI agents, MCP servers and agent skills.

ai-securitycode-analysisdynamic-analysis-sandboxing+3
3.1k1 day ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

ai-securitycommand-and-controldata-exfiltration+7
3763 months ago
cryptoptic preview

cryptoptic

GitHubnationwide-group-oss/cryptoptic

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

code-analysisconfiguration-auditingcryptography+6
4 days ago
chain-bench preview

chain-bench

GitHubaquasecurity/chain-bench

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

configuration-auditingdevsecopssupply-chain-security+1
7722 years ago
murphysec preview

murphysec

GitHubmurphysecurity/murphysec

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

supply-chain-securityvulnerability-scanners
1.8k5 months ago
fix-react2shell-next preview

fix-react2shell-next

GitHubvercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

code-analysisdevsecopsscripting-automation+3
4019 months ago
GitHound preview

GitHound

GitHubspecterops/githound

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

cloud-securityidentity-access-managementinformation-gathering+4
1471 month ago
hol-guard preview

hol-guard

GitHubhashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

ai-securityconfiguration-auditingdefensive-tools+7
6346 days ago
jetty-line-check preview

jetty-line-check

GitHubxiaoqimikko/jetty-line-check

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on…

configuration-auditingdefensive-toolsstatic-analysis+4
8 days ago
deepsec preview

deepsec

GitHubvercel-labs/deepsec

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

ai-securitycode-analysisdevsecops+5
8.0k3 days ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
462 days ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

ai-securitycloud-securitycommand-and-control+7
21619h 15m ago
wolfssl preview

wolfssl

GitHubwolfssl/wolfssl

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

cloud-securitycryptographyembedded-systems-security+6
2.9k0 days ago
log4jhound preview

log4jhound

GitHubmebibite/log4jhound

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

code-analysisdevsecopsstatic-analysis+2
4 years ago
agent-bom preview

agent-bom

GitHubmsaad00/agent-bom

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

ai-securitycloud-securitycontainer-security+6
3115h 13m ago
jit preview

jit

GitHubjitpass/jit

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

authentication-authorizationconfiguration-auditingdevsecops+3
1606 days ago
Previous12345Next