Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
452 results
react2shell-scanner preview

react2shell-scanner

GitHubgensecaihq/react2shell-scanner

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

code-analysiscontainer-securitydevsecops+4
58
9 months ago
clawguard preview

clawguard

GitHubsafeagent-beihang/clawguard

Enterprise AI agent security toolkit providing pre-flight auditing, configuration hardening, runtime threat detection, and active defense against…

ai-securityanomaly-detectioncode-analysis+5
505 months ago
CVE-2026-67595 preview

CVE-2026-67595

GitHubilhomjonr/cve-2026-67595

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

command-and-controlmalware-analysisstatic-analysis+4
1 month ago
CVE-2024-3094 preview
Archived

CVE-2024-3094

GitHubteyhouse/cve-2024-3094

K8S and Docker Vulnerability Check for CVE-2024-3094

cloud-securitycontainer-securitydevsecops+3
112 years ago
xzutils_backdoor_obfuscation preview

xzutils_backdoor_obfuscation

GitHubthomrgn/xzutils_backdoor_obfuscation

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)

binary-exploitationeducationexploitation+4
10 months ago
tomcat-line-check preview

tomcat-line-check

GitHubxiaoqimikko/tomcat-line-check

CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers…

configuration-auditingsupply-chain-securityvulnerability-scanners+1
6 days ago
CTWall preview

CTWall

GitHubcybergabisoft/ctwall

CTWall (ChainThreatWall) platform helps Security, DevOps, and Product teams make risk decisions faster by using SBOM/BOM data to identify malware in…

cloud-securitycontainer-securitydevsecops+6
12 months ago
log4j-recognizer preview

log4j-recognizer

GitHubscitotec/log4j-recognizer

A Java helper to identify log4j in the current classpath

defensive-toolssupply-chain-securityvulnerability-analysis
24 years ago
bash-cve-2014-6271-fixes preview

bash-cve-2014-6271-fixes

GitHubdlitz/bash-cve-2014-6271-fixes

Curated collection of verified patches for the Shellshock (CVE-2014-6271) bash vulnerability, with upstream, Debian, and custom patches plus SHA256…

curated-resourceseducationsupply-chain-security+1
11 years ago
Android-Projector-C2-Malware preview

Android-Projector-C2-Malware

GitHubkavan00/android-projector-c2-malware

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

android-securitycommand-and-controldigital-forensics+9
185 months ago
threat-intel-cve-2024-3094 preview

threat-intel-cve-2024-3094

GitHub24owais/threat-intel-cve-2024-3094

Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)

educationincident-responsepapers-research+3
11 year ago
CVE-2024-24590-ClearML-RCE-CMD-POC preview

CVE-2024-24590-ClearML-RCE-CMD-POC

GitHubdiegogarciayala/cve-2024-24590-clearml-rce-cmd-poc

CVE-2024-24590 ClearML RCE&CMD POC

command-and-controlexploitationpayload-generation+3
92 years ago
LLM-MCP-Security-Field-Guide preview

LLM-MCP-Security-Field-Guide

GitHubpathakabhi24/llm-mcp-security-field-guide

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

ai-securitycurated-resourceseducation+7
45 months ago
CVE-2026-26831 preview

CVE-2026-26831

GitHubzebberncve/cve-2026-26831

Advisory for textract ⌯⌲ 15 000 weekly downloads

code-analysiseducationexploitation+3
5 months ago
reposaur preview
Archived

reposaur

GitHubreposaur/reposaur

Open source compliance tool for development platforms.

cloud-securitycode-analysisconfiguration-auditing+5
2862 years ago
log4j preview

log4j

GitHubopen-aims/log4j

Patched Log4j 1.2.17 library with the vulnerable JMSAppender class removed to mitigate CVE-2021-4104, intended as a drop-in replacement for affected…

devsecopssupply-chain-securityvulnerability-analysis
4 years ago
CVE-2024-3094-info preview

CVE-2024-3094-info

GitHubmightysai1997/cve-2024-3094-info

Curated collection of resources and analysis documenting the CVE-2024-3094 supply-chain backdoor in XZ Utils, including security advisories,…

curated-resourceseducationinformation-gathering+3
2 years ago
opentaint preview

opentaint

GitHubseqra/opentaint

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

ai-securityapi-securitycode-analysis+7
1574 days ago
Previous1…101112…26Next