Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
446 results
local-log4j-vuln-scanner preview
Archived

local-log4j-vuln-scanner

GitHubhillu/local-log4j-vuln-scanner

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

code-analysisdevsecopsstatic-analysis+3
371
4 years ago
grype preview

grype

GitHubanchore/grype

A vulnerability scanner for container images and filesystems

container-escapecontainer-securitydevsecops+4
12.8k12h 16m ago
ElfDoor-gcc preview

ElfDoor-gcc

GitHubmatheuzsecurity/elfdoor-gcc

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

binary-exploitationpersistence-mechanismssupply-chain-security
1331 year ago
libwebp-checker preview

libwebp-checker

GitHubmurphysecurity/libwebp-checker

A tool for finding vulnerable libwebp(CVE-2023-4863)

code-analysisstatic-analysissupply-chain-security+2
212 years ago
scan-cve-2018-8115 preview

scan-cve-2018-8115

GitHubaquasecurity/scan-cve-2018-8115

CLI tool that verifies Docker images for CVE-2018-8115 by checking layers for malicious files, helping ensure safe pulls from Docker Hub.

container-securitymisconfigurationstatic-analysis+2
78 years ago
tanstack-compromise-checker preview

tanstack-compromise-checker

GitHubfabriziosalmi/tanstack-compromise-checker

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

container-securitydevsecopsforensics+7
21 month ago
pqaudit preview

pqaudit

GitHubpqcworld/pqaudit

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

code-analysiscryptographydevsecops+5
34 months ago
react2shell-scanner preview

react2shell-scanner

GitHubnxgn-kd01/react2shell-scanner

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

code-analysisdevsecopsexploitation+3
37 months ago
log4j-scanner-CVE-2021-44228 preview

log4j-scanner-CVE-2021-44228

GitHubgeorge-petrakis/log4j-scanner-cve-2021-44228

Simple tool for scanning entire directories for attempts of CVE-2021-44228

code-analysismisconfigurationstatic-analysis+3
24 years ago
scan-shai-hulud preview

scan-shai-hulud

GitHubqi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

forensicsincident-responseioc-management+6
13 months ago
inspec_cve_2019_15224 preview

inspec_cve_2019_15224

GitHubchef-cft/inspec_cve_2019_15224

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

configuration-auditingincident-responsemalware-analysis+2
17 years ago
mini-shai-hulud-detector preview

mini-shai-hulud-detector

GitHubprashanthnataraj/mini-shai-hulud-detector

One-command scanner for the Mini Shai-Hulud npm supply-chain worm (CVE-2026-45321). Detect before rotating tokens.

forensicsincident-responsemalware-analysis+3
3 months ago
jsPDF-Bulk-Detector-CVE-2025-68428- preview

jsPDF-Bulk-Detector-CVE-2025-68428-

GitHubnurjaman2004/jspdf-bulk-detector-cve-2025-68428-

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

code-analysisinformation-gatheringreconnaissance+3
17 months ago
scavenger_scanner preview

scavenger_scanner

GitHubpaspke/scavenger_scanner

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

incident-responseioc-managementmalware-analysis+3
4 months ago
xz_cve-2024-3094_detection preview

xz_cve-2024-3094_detection

GitHubbioless/xz_cve-2024-3094_detection

Script to detect CVE-2024-3094.

code-analysisstatic-analysissupply-chain-security+2
2 years ago
external_zlib_CVE-2022-37434 preview

external_zlib_CVE-2022-37434

GitHubtrinadh465/external_zlib_cve-2022-37434

General-purpose data compression library implementing the zlib, deflate, and gzip formats, with thread-safe functions and cross-platform build…

binary-analysisexploitationfuzzing+3
2 years ago
L4J-Vuln-Patch preview
Archived

L4J-Vuln-Patch

GitHubjacobtread/l4j-vuln-patch

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

exploitationmisconfigurationsupply-chain-security+2
54 years ago
hotpatch-for-apache-log4j2 preview

hotpatch-for-apache-log4j2

GitHubcorretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

defensive-toolsexploitationincident-response+2
4973 years ago
Previous1…456…25Next