Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
442 results
clawguard preview

clawguard

GitHubsafeagent-beihang/clawguard

Enterprise AI agent security toolkit providing pre-flight auditing, configuration hardening, runtime threat detection, and active defense against…

ai-securityanomaly-detectioncode-analysis+5
50
5 months ago
cs50-cybersecurity-final-project preview

cs50-cybersecurity-final-project

GitHubmhicairo-hue/cs50-cybersecurity-final-project

Technical analysis of the XZ Utils backdoor (CVE-2024-3094), explaining the supply chain attack, obfuscation techniques, and impact on OpenSSH via…

curated-resourceseducationmalware-analysis+2
17h 8m ago
gha-lab-00d54c717d preview

gha-lab-00d54c717d

GitHubpvharmo2/gha-lab-00d54c717d

Security-research lab: CVE-2026-47172 (workflow_run pwn request in deploy.yaml) — flattened snapshot of duck-organization/questbot at 1903b2f

curated-resourcesdevsecopseducation+2
17h 35m ago
gha-lab-8aba6b05dc preview

gha-lab-8aba6b05dc

GitHubpvharmo2/gha-lab-8aba6b05dc

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of…

cloud-securitycurated-resourceseducation+3
22h 22m ago
gha-lab-5511dc3f73 preview

gha-lab-5511dc3f73

GitHubpvharmo2/gha-lab-5511dc3f73

Authorized security-research lab reproducing CVE-2026-45131 (pwn request in .github/workflows/pull-request.yaml) — snapshot of…

cloud-securitydevsecopseducation+2
1 day ago
gha-lab-5bce203f66 preview

gha-lab-5bce203f66

GitHubpvharmo2/gha-lab-5bce203f66

Security-research lab: reproduction of CVE-2026-41249 (GHSA-q58j-g3f4-h26h) — pull_request_target pwn request in .github/workflows/static.yml,…

curated-resourcesdevsecopseducation+2
1 day ago
gha-lab-456dd8a245 preview

gha-lab-456dd8a245

GitHubpvharmo2/gha-lab-456dd8a245

Security-research lab reproducing CVE-2026-41414 (pull_request_target pwn in .github/workflows/pr.yml) — snapshot of skim-rs/skim @ ca986f4, not a…

curated-resourceseducationexploitation+2
1 day ago
netty-http2-check preview

netty-http2-check

GitHubxiaoqimikko/netty-http2-check

Offline Java tool that scans jars and versions to determine exposure to seven netty-codec-http2 CVEs, recommending the single patched version that…

configuration-auditingdevsecopssupply-chain-security+2
2 days ago
gha-lab-3f1ff30e9c preview

gha-lab-3f1ff30e9c

GitHubpvharmo2/gha-lab-3f1ff30e9c

Authorized security-research lab reproducing CVE-2026-31852 (jellyfin/jellyfin-ios pull_request_target pwn in code-quality.yml) — isolated snapshot,…

cloud-securitycurated-resourcesdevsecops+2
3 days ago
gha-lab-ca4fa82ac5 preview

gha-lab-ca4fa82ac5

GitHubpvharmo2/gha-lab-ca4fa82ac5

Security-research lab: reproduction of CVE-2026-29075 (GHSA-3j55-5q6x-2h48) in mesa/mesa benchmarks.yml pull_request_target workflow — single-commit…

curated-resourcesdevsecopseducation+3
3 days ago
gha-lab-fb6df3d456 preview

gha-lab-fb6df3d456

GitHubpvharmo2/gha-lab-fb6df3d456

Authorized security-research lab reproducing CVE-2025-46820 (GHSA-cwj7-6v67-2cm4): GITHUB_TOKEN persisted into publicly downloadable CI artifacts in…

cloud-securitycurated-resourceseducation+2
4 days ago
gha-lab-2f775f277c preview

gha-lab-2f775f277c

GitHubpvharmo2/gha-lab-2f775f277c

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

cloud-securitycurated-resourcesdevsecops+2
4 days ago
gha-lab-f894926966 preview

gha-lab-f894926966

GitHubpvharmo2/gha-lab-f894926966

Authorized security-research reproduction lab for CVE-2025-54415 (GHSA-g5hx-xv45-9whg): astronomer/dag-factory snapshot at 464c75a —…

curated-resourcesdevsecopseducation+2
3 days ago
mojarra-2.2.13-patched preview

mojarra-2.2.13-patched

GitHubthelonelycoder/mojarra-2.2.13-patched

Backport of the CVE-2020-6950 security fix to Mojarra 2.2.13, providing a patched jsf-impl JAR with minimal, reviewable changes for legacy…

curated-resourceseducationsupply-chain-security+1
3 days ago
thymeleaf-check preview

thymeleaf-check

GitHubxiaoqimikko/thymeleaf-check

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

configuration-auditingdevsecopsstatic-analysis+2
3 days ago
gha-lab-b1fe4918c0 preview

gha-lab-b1fe4918c0

GitHubpvharmo2/gha-lab-b1fe4918c0

Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's…

curated-resourceseducationsupply-chain-security+1
4 days ago
LR-WebPKI preview

LR-WebPKI

GitHubnserser/lr-webpki

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

cloud-infrastructure-securitycryptographyeducation+2
8 days ago
gha-lab-becf103a54 preview

gha-lab-becf103a54

GitHubpvharmo2/gha-lab-becf103a54

Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration…

cloud-securitycurated-resourceseducation+2
5 days ago
Previous12…25Next