Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
InfraTest preview

InfraTest

GitHubroy-aladin/infratest

DO NOT FORK, DEPLOY, OR USE FOR ANYTHING BUT LEARNING. These requirements are vulnerable to CVE-2024-39689

cloud-securityconfiguration-auditingeducation+2
2 years ago
log4j-patched preview

log4j-patched

GitHubaschen/log4j-patched

Provide patched version of Log4J against CVE-2021-44228 and CVE-2021-45046 as well as a script to manually patch it yourself

curated-resourceseducationscripting-automation+2
14 years ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k2 months ago
My-Presentation-Slides preview

My-Presentation-Slides

GitHubdhiyaneshgeek/my-presentation-slides

Collection's of Tech Talk that are presented by me :)

api-securitycloud-securitycurated-resources+6
1011 month ago
AI-SPM preview

AI-SPM

GitHubdshapi/ai-spm

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

ai-securitycloud-securitymisconfiguration+3
134 months ago
trufflehog preview

trufflehog

GitHubtrufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

cloud-securitycode-analysisdevsecops+6
27.9k8h 45m ago
CVE-2024-24590 preview

CVE-2024-24590

GitHubjunnythemarksman/cve-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously…

exploitationpayload-generationpenetration-testing+3
12 years ago
bidi_char_detector preview
Archived

bidi_char_detector

GitHubmaweil/bidi_char_detector

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

code-analysismisconfigurationsecret-detection+3
63 years ago
CVE-2017-1000117 preview

CVE-2017-1000117

GitHubtimwr/cve-2017-1000117

Proof of concept of CVE-2017-1000117

educationexploitationpenetration-testing+2
79 years ago
capslock preview

capslock

GitHubgoogle/capslock

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

code-analysisdevsecopsstatic-analysis+2
1.2k12 days ago
local-log4j-vuln-scanner preview
Archived

local-log4j-vuln-scanner

GitHubhillu/local-log4j-vuln-scanner

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

code-analysisdevsecopsstatic-analysis+3
3714 years ago
CVE-2024-24787-PoC preview

CVE-2024-24787-PoC

GitHublourc0d3/cve-2024-24787-poc

CVE-2024-24787 Proof of Concept

binary-exploitationeducationexploitation+2
52 years ago
terrier preview

terrier

GitHubheroku/terrier

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

container-securityhash-analysissupply-chain-security+1
2273 months ago
CVE-2025-53547-POC preview

CVE-2025-53547-POC

GitHubdvkunion/cve-2025-53547-poc

CVE-2025-53547 one of poc code

command-and-controlexploitationpayload-development+2
91 year ago
CVE-2021-43616 preview

CVE-2021-43616

GitHubicatalina/cve-2021-43616

Demonstration of CVE-2021-43616: npm `ci` command ignoring package-lock.json, causing unintended dependency version installation and supply-chain…

educationsupply-chain-securityvulnerability-analysis
34 years ago
ai-ide-config-guard preview

ai-ide-config-guard

GitHubtrerb/ai-ide-config-guard

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

code-analysiseducationmisconfiguration+4
4 months ago
magento-swf-patched-CVE-2011-2461 preview

magento-swf-patched-CVE-2011-2461

GitHubu-maxx/magento-swf-patched-cve-2011-2461

Patched version of the uploader.swf and uploaderSingle.swf to fix CVE-2011-2461

exploitationstatic-analysissupply-chain-security+2
11 years ago
claude-code-backdoor preview

claude-code-backdoor

GitHubs0ld13rr/claude-code-backdoor

Backdooring Claude Code via hooks in settings.json. Authorized use only!

educationmalware-analysispenetration-testing+4
885 months ago
Previous123Next