Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
120 results
Linux---Security---Detect-and-Mitigate-CVE-2024-3094 preview

Linux---Security---Detect-and-Mitigate-CVE-2024-3094

GitHublaxmikumari615/linux---security---detect-and-mitigate-cve-2024-3094

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only…

educationincident-responsesupply-chain-security+2
1 year ago
log4shell preview

log4shell

GitHubhozyx/log4shell

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

code-analysisdevsecopsstatic-analysis+3
4 years ago
CVE-2023-37478_npm_vs_pnpm preview

CVE-2023-37478_npm_vs_pnpm

GitHubtrevorgkann/cve-2023-37478_npm_vs_pnpm

CVE-2023-37478 showcases how a difference in npm and pnpm install packages that could be exploited by a well crafted tar.gz packge. This repo shows a…

educationexploitationlabs-practice+3
2 years ago
springhound preview

springhound

GitHubmebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

code-analysismisconfigurationstatic-analysis+2
4 years ago
git-cveissues preview

git-cveissues

GitHubsondermc/git-cveissues

vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional,…

configuration-auditingdevsecopsgeneral-purpose-utilities+3
3 years ago
CVE-2026-5817-PoC preview

CVE-2026-5817-PoC

GitHubgouldnicholas/cve-2026-5817-poc

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

ai-securitycontainer-escapecontainer-security+4
3 months ago
jit preview

jit

GitHubjitpass/jit

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

authentication-authorizationconfiguration-auditingdevsecops+3
145 days ago
yolo-cage preview
Archived

yolo-cage

GitHubborenstein/yolo-cage

AI coding agents that can't exfiltrate secrets or merge their own PRs.

ai-securitycloud-securitycontainer-security+7
1096 months ago
CVE-2021-44228_scanner preview
Archived

CVE-2021-44228_scanner

GitHubcertcc/cve-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

code-analysisincident-responsestatic-analysis+3
3504 years ago
anchore-engine preview
Archived

anchore-engine

GitHubanchore/anchore-engine

A service that analyzes docker images and scans for vulnerabilities

cloud-securitycontainer-securitydevsecops+3
1.6k3 years ago
patched-bash-4.3 preview

patched-bash-4.3

GitHubryancnelson/patched-bash-4.3

patched-bash-4.3 for CVE-2014-6271

general-purpose-utilitiessupply-chain-securityvulnerability-analysis
11 years ago
golang-x-text preview

golang-x-text

GitHubkatekeiroz-dev/golang-x-text

golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24

general-purpose-utilitiessupply-chain-securityutilities-frameworks
3 days ago
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
27.5k7h 5m ago
deepsec preview

deepsec

GitHubvercel-labs/deepsec

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

ai-securitycode-analysisdevsecops+5
7.8k2 days ago
skill-scanner preview

skill-scanner

GitHubcisco-ai-defense/skill-scanner

Security Scanner for Agent Skills

ai-securitycode-analysisdevsecops+9
2.4k16 days ago
trivy-action preview

trivy-action

GitHubaquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

cloud-securitycode-analysiscontainer-security+5
1.4k6 days ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k1 month ago
shim preview

shim

GitHubrhboot/shim

UEFI shim loader

authenticationcryptographydefensive-tools+3
1.1k24 days ago
Previous1234567Next