Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
276 results
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
31
3 months ago
LR-WebPKI preview

LR-WebPKI

GitHubnserser/lr-webpki

Reference implementation of LR+ post-quantum authentication over WebPKI CA context, with corpus pipeline, reconstruction, evaluation, and provenance…

cloud-infrastructure-securitycryptographyeducation+2
9 days ago
eclipse__hawkbit_CVE-2020-27219_0-3-0M6 preview

eclipse__hawkbit_CVE-2020-27219_0-3-0M6

GitHubshoucheng3/eclipse__hawkbit_cve-2020-27219_0-3-0m6

Domain-independent back end for rolling out software updates to constrained edge devices, controllers, and gateways over IP-based infrastructure,…

cloud-securitycontainer-securitydevsecops+3
1 year ago
log4jjndilookupremove preview

log4jjndilookupremove

GitHublukepasek/log4jjndilookupremove

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

incident-responsemisconfigurationscripting-automation+2
4 years ago
weave-gitops preview

weave-gitops

GitHubweaveworks/weave-gitops

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
1.1k7 months ago
modelscan preview

modelscan

GitHubprotectai/modelscan

Protection against Model Serialization Attacks

adversarial-attackai-securitydefensive-tools+5
7736 months ago
flar preview

flar

GitHubswelljoe/flar

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

ai-securitycontainer-securitydevsecops+5
551 month ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

ai-securitycommand-and-controldata-exfiltration+7
3702 months ago
smokedmeat preview

smokedmeat

GitHubboostsecurityio/smokedmeat

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

cloud-securitycommand-and-controleducation+9
3771 month ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

ai-securitycloud-securitycommand-and-control+7
21011h 15m ago
malicious-devfile-registry preview

malicious-devfile-registry

GitHubdoyensec/malicious-devfile-registry

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

exploitationpenetration-testingred-teaming+3
151 year ago
SkillsGuard preview

SkillsGuard

GitHubteycir/skillsguard

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

ai-securitycode-analysiscommand-and-control+8
152 months ago
Sovereign-Echo-33017 preview

Sovereign-Echo-33017

GitHubsimoesctt/sovereign-echo-33017

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

ai-securityexploitationpenetration-testing+4
5 months ago
CocoaPods-RCE_CVE-2024-38366 preview

CocoaPods-RCE_CVE-2024-38366

GitHubreefspek/cocoapods-rce_cve-2024-38366

CocoaPods RCE Vulnerability CVE-2024-38366

command-and-controlexploitationpayload-development+5
12 years ago
LlamaStack-RCE-Deterministic-Supply-Chain-Exploitation-Hardening-Framework-CVE-2024-50050- preview

LlamaStack-RCE-Deterministic-Supply-Chain-Exploitation-Hardening-Framework-CVE-2024-50050-

GitHubsastraadiwiguna-purpleeliteteaming/llamastack-rce-deterministic-supply-chain-exploitation-hardening-framework-cve-2024-50050-

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

ai-securitybinary-exploitationcommand-and-control+9
7 months ago
wardn preview

wardn

GitHubrohansx/wardn

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

api-securityauthentication-authorizationcloud-security+6
362 months ago
gitleaks preview

gitleaks

GitHubgitleaks/gitleaks

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

code-analysisdevsecopssecret-detection+3
29.2k1 month ago
rustsec preview

rustsec

GitHubrustsec/rustsec

RustSec API & Tooling

code-analysisdevsecopsstatic-analysis+3
1.9k7 days ago
Previous12…16Next