Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
256 results
PSCF preview

PSCF

GitHubowasp/pscf
curated-resourcesdevsecopseducation+2
2810 months ago
VulnReach preview

VulnReach

GitHubowasp/vulnreach

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

code-analysisdevsecopsdynamic-analysis-sandboxing+5
131 day ago
sloppy-joe preview

sloppy-joe

GitHubbrennhill/sloppy-joe

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

code-analysisdevsecopseducation+5
324 months ago
DonkAI preview

DonkAI

GitHubowasp/donkai

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

ai-securityctfeducation+6
122 months ago
vibe-coding-security preview

vibe-coding-security

GitHubboxed-dev/vibe-coding-security

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

ai-securityapi-securityauthentication+9
1412 days ago
ci-supplychain-guard preview

ci-supplychain-guard

GitHubotsmane-ahmed/ci-supplychain-guard

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

code-analysiscontainer-securitydevsecops+5
286 months ago
mininode preview

mininode

GitHubwspr-ncsu/mininode

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

code-analysiseducationpapers-research+3
213 years ago
remic preview

remic

GitHubknqyf263/remic

Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependencies

supply-chain-securityvulnerability-scanners
237 years ago
kprotect preview

kprotect

GitHubkhoinp1012/kprotect

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

authentication-authorizationcloud-securitydefensive-tools+4
365 months ago
CVE-2026-43813 preview

CVE-2026-43813

GitHubeastarctica/cve-2026-43813

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

authentication-authorizationbinary-analysiscloud-security+5
922 days ago
malicious-devfile-registry preview

malicious-devfile-registry

GitHubdoyensec/malicious-devfile-registry

Exploit for CVE-2024-0402 in Gitlab

exploitationpenetration-testingred-teaming+3
151 year ago
scopeblind-gateway preview

scopeblind-gateway

GitHubtomjwxf/scopeblind-gateway

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

ai-securityapi-securityauthentication-authorization+6
94 months ago
CVE-2021-26700 preview

CVE-2021-26700

GitHubjackadamson/cve-2021-26700

RCE in NPM VSCode Extension

code-analysiseducationexploitation+3
205 years ago
CVE-2023-51385_test preview

CVE-2023-51385_test

GitHubltmthink/cve-2023-51385_test

一个验证对CVE-2023-51385

educationexploitationsupply-chain-security+2
72 years ago
vexhub-crawler preview

vexhub-crawler

GitHubaquasecurity/vexhub-crawler

Collect VEX documents and update VEX Hub

crawlerinformation-gatheringsupply-chain-security+3
79 months ago
Package-Inferno preview

Package-Inferno

GitHubmhaggis/package-inferno

A Public Package Scanner for The Community

cloud-securitycontainer-securitydevsecops+6
137 months ago
log4j-samples preview

log4j-samples

GitHubmergebase/log4j-samples

Public testing data. Samples of log4j library versions to help log4j scanners / detectors improve their accuracy for detecting CVE-2021-45046 and…

curated-resourceseducationsupply-chain-security+2
144 years ago
confusable-vision preview

confusable-vision

GitHubpaultendo/confusable-vision

793 confusable pairs missing from Unicode TR39, world-first cross-script dataset, font-aware SSIM scoring across 230 fonts and 22,000+ characters

curated-resourceseducationosint+5
115 months ago
Previous1…567…15Next