Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
452 results
mcp-server-attestation preview

mcp-server-attestation

GitHubstudiomeyer-io/mcp-server-attestation

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

code-analysiscommand-and-controlcryptography+3
8 days ago
CVE-2026-40175 preview

CVE-2026-40175

GitHub0xblackash/cve-2026-40175

CVE-2026-40175

cloud-securityeducationexploitation+3
5 months ago
CVE-2025-48384-test preview

CVE-2025-48384-test

GitHubbeishanxueyuan/cve-2025-48384-test

Reproduction of CVE-2025-48384 demonstrating a Git submodule path traversal vulnerability, with step-by-step commands to recreate the exploit.

code-analysisexploitationsupply-chain-security+1
11 year ago
cve-2024-3094-tools preview

cve-2024-3094-tools

GitHubjfrog/cve-2024-3094-tools

Shell-based scanner to detect the XZ Backdoor (CVE-2024-3094) vulnerability in files and directories, enabling rapid identification and mitigation of…

forensicsincident-responsemalware-analysis+3
452 years ago
AI-SPM preview

AI-SPM

GitHubdshapi/ai-spm

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

ai-securitycloud-securitymisconfiguration+3
134 months ago
log4jhound preview

log4jhound

GitHubmebibite/log4jhound

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

code-analysisdevsecopsstatic-analysis+2
4 years ago
springhound preview

springhound

GitHubmebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

code-analysismisconfigurationstatic-analysis+2
4 years ago
AWS-Tough-Library-Multiple-CVEs preview

AWS-Tough-Library-Multiple-CVEs

GitHubmurataydemir/aws-tough-library-multiple-cves

Issue with tough, versions prior to 0.20.0 (Multiple CVEs)

educationpapers-researchsupply-chain-security+1
11 year ago
go-get-RCE preview

go-get-RCE

GitHubsaptaktdk/go-get-rce

This is the exploit of CVE-2018-6574: go get RCE

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2024-3094-XZ-Backdoor-Detector preview

CVE-2024-3094-XZ-Backdoor-Detector

GitHubdevjanger/cve-2024-3094-xz-backdoor-detector

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

forensicsincident-responsemalware-analysis+3
2 years ago
xz-utils-vuln-checker preview

xz-utils-vuln-checker

GitHubharekrishnarai/xz-utils-vuln-checker

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…

curated-resourceseducationsupply-chain-security+2
12 years ago
CVE-2026-29786 preview

CVE-2026-29786

GitHubjvr2022/cve-2026-29786

Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

code-analysisexploitationsupply-chain-security+2
16 months ago
inspec_cve_2019_15224 preview

inspec_cve_2019_15224

GitHubchef-cft/inspec_cve_2019_15224

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

configuration-auditingincident-responsemalware-analysis+2
17 years ago
CVE-2024-3094 preview

CVE-2024-3094

GitHubmightysai1997/cve-2024-3094

Shell scripts to detect CVE-2024-3094 backdoor in liblzma5 across Kubernetes pods and Docker containers, with SBOM generation via Trivy for…

cloud-securitycontainer-securitydevsecops+3
2 years ago
Detection-script-for-cve-2021-23358 preview

Detection-script-for-cve-2021-23358

GitHubekamsinghwalia/detection-script-for-cve-2021-23358

Detection script for cve-2021-23358

code-analysisstatic-analysissupply-chain-security+2
13 years ago
ElfDoor-gcc preview

ElfDoor-gcc

GitHubmatheuzsecurity/elfdoor-gcc

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

binary-exploitationpersistence-mechanismssupply-chain-security
1351 year ago
shai-hulud-scan preview

shai-hulud-scan

GitHubshayr1/shai-hulud-scan

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

educationforensicsincident-response+5
14 months ago
stylesmuggler-adobe-patches preview

stylesmuggler-adobe-patches

GitHubdisrex-group/stylesmuggler-adobe-patches

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for…

configuration-auditingdevsecopssupply-chain-security+1
47 days ago
Previous1…456…26Next