Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
646 results
supply-chain-monitor preview

supply-chain-monitor

GitHubelastic/supply-chain-monitor

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

code-analysisincident-responsemalware-analysis+3
531
5 months ago
DependencyCheck preview

DependencyCheck

GitHubdependency-check/dependencycheck

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

devsecopssupply-chain-securityvulnerability-analysis+1
7.7k6 days ago
Owasp-top-10-k8s-2025 preview

Owasp-top-10-k8s-2025

GitHubhac01/owasp-top-10-k8s-2025

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

cloud-securitycontainer-securityctf+8
481 month ago
vexhub preview

vexhub

GitHubaquasecurity/vexhub

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

devsecopsinformation-gatheringsupply-chain-security+2
395 months ago
SafeForge preview

SafeForge

GitLabroxanne_ardary/safeforge

SafeForge is an open-source mobile app hub built on GitLab that enables developers to build, upload, and share applications in a secure, AI-verified…

ai-securitydynamic-analysis-sandboxingeducation+8
22 days ago
SBOM-VEX-Taint-Analysis preview

SBOM-VEX-Taint-Analysis

GitHubowasp/sbom-vex-taint-analysis

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

ai-securitycurated-resourceseducation+3
31 month ago
CVE-2025-46295-fix-fms preview

CVE-2025-46295-fix-fms

GitHubsoliantconsulting/cve-2025-46295-fix-fms

Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with…

configuration-auditingdevsecopsscripting-automation+3
18 months ago
node-prompt-here preview

node-prompt-here

GitHubdannyendortest/node-prompt-here

Deliberately vulnerable Node.js demo target for CVE-2020-7602, used to showcase automated dependency vulnerability detection and one-click PR-based…

educationlabs-practicesupply-chain-security+2
3 months ago
invokeai preview

invokeai

GitHubdannyendortest/invokeai

Synthetic demo target for CVE-2024-10821 vulnerability detection and automated fix via compensating control. Demonstrates one-click PR-based…

devsecopseducationmisconfiguration+3
3 months ago
-Ruby-dl-handle.c-CVE-2009-5147- preview

-Ruby-dl-handle.c-CVE-2009-5147-

GitHubzhangyongbo100/-ruby-dl-handle.c-cve-2009-5147-

Community-maintained database of Ruby gem security advisories with structured CVE data, CVSS scores, and patched version requirements. Integrates…

code-analysiscurated-resourceseducation+3
7 years ago
vuln_test_repo_public_ruby_gemfile_cve-2016-6317 preview

vuln_test_repo_public_ruby_gemfile_cve-2016-6317

GitHubkavgan/vuln_test_repo_public_ruby_gemfile_cve-2016-6317

Detects known vulnerabilities in Ruby Gemfile dependencies by scanning for specific CVEs, enabling automated security checks in development pipelines.

code-analysisdevsecopsstatic-analysis+2
9 years ago
jenkinsci__workflow-multibranch-plugin_CVE-2022-25175_706-vd43c65dec013 preview

jenkinsci__workflow-multibranch-plugin_CVE-2022-25175_706-vd43c65dec013

GitHubshoucheng3/jenkinsci__workflow-multibranch-plugin_cve-2022-25175_706-vd43c65dec013

Exploit for CVE-2022-25175 targeting Jenkins Pipeline: Multibranch plugin, enabling automated exploitation of a specific vulnerability in CI/CD…

code-analysisdevsecopsexploitation+3
10 months ago
proxy preview

proxy

GitHubgit-pkgs/proxy

A lightweight caching proxy for package registries.

api-securitycloud-securitydevsecops+2
1873 days ago
gha-lab-232af4821f preview

gha-lab-232af4821f

GitHubpvharmo2/gha-lab-232af4821f

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in…

devsecopseducationsupply-chain-security+1
1 day ago
gha-lab-83342297e0 preview

gha-lab-83342297e0

GitHubpvharmo2/gha-lab-83342297e0

Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection…

curated-resourceseducationsupply-chain-security+1
2 days ago
safety preview

safety

GitHubpyupio/safety

Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.

code-analysisdevsecopssupply-chain-security+1
2.0k4 days ago
murphysec preview

murphysec

GitHubmurphysecurity/murphysec

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

supply-chain-securityvulnerability-scanners
1.8k4 months ago
lunasec preview

lunasec

GitHublunasec-io/lunasec

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

devsecopssecret-detectionsupply-chain-security+1
1.5k2 years ago
Previous12…36Next