Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
272 results
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
18
23 days ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
486h 47m ago
agent-bom preview

agent-bom

GitHubmsaad00/agent-bom

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

ai-securitycloud-securitycontainer-security+6
3115h 2m ago
CVE-2026-0596-Reproduction preview

CVE-2026-0596-Reproduction

GitHubsparshbiswas-ai/cve-2026-0596-reproduction

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

binary-exploitationeducationexploitation+7
4 months ago
CVE-2021-30005-POC preview

CVE-2021-30005-POC

GitHubatorralba/cve-2021-30005-poc

Proof-of-concept demonstrating arbitrary command execution via malicious virtual environment activation scripts in PyCharm before 2020.3.4,…

code-analysiseducationexploitation+2
25 years ago
wardn preview

wardn

GitHubrohansx/wardn

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

api-securityauthentication-authorizationcloud-security+6
363 days ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubjvr2022/cve-2026-31802

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

exploitationsupply-chain-securityvulnerability-analysis+1
16 months ago
github-dev-token-steal-poc preview

github-dev-token-steal-poc

GitHubammaraskar/github-dev-token-steal-poc

Proof-of-concept exploit demonstrating a GitHub OAuth token-stealing vulnerability via crafted developer workflow triggers, enabling unauthorized…

authenticationexploitationsupply-chain-security+2
204 months ago
spring-retry-toolkit preview

spring-retry-toolkit

GitHubnichetoolkit/spring-retry-toolkit

spring retry 1.3.x fix with niche toolkit for CVE-2026-41710

supply-chain-securityvulnerability-analysisweb-security
1 month ago
NodeJS-Tar-Symlink-Exploit-CVE-2026-29786 preview

NodeJS-Tar-Symlink-Exploit-CVE-2026-29786

GitHubrohitberiwala/nodejs-tar-symlink-exploit-cve-2026-29786

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

exploitationsupply-chain-securityvulnerability-analysis+1
16 months ago
snyk-js-jquery-174006 preview
Archived

snyk-js-jquery-174006

GitHubdanielruf/snyk-js-jquery-174006

patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428

code-analysissupply-chain-securityvulnerability-analysis+1
284 years ago
L4J-Vuln-Patch preview
Archived

L4J-Vuln-Patch

GitHubjacobtread/l4j-vuln-patch

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

exploitationmisconfigurationsupply-chain-security+2
54 years ago
secfixes-tracker preview

secfixes-tracker

GitHubaquasecurity/secfixes-tracker

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

devsecopsinformation-gatheringsupply-chain-security+2
83 months ago
advisories preview

advisories

GitHubjustinsteven/advisories

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

cloud-securitycurated-resourceseducation+3
2723 years ago
AuraBorealisApp preview
Archived

AuraBorealisApp

GitHubiqtlabs/auraborealisapp

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

code-analysismalware-analysisstatic-code-analysis+2
204 years ago
vexhub-crawler preview

vexhub-crawler

GitHubaquasecurity/vexhub-crawler

Collect VEX documents and update VEX Hub

crawlerinformation-gatheringsupply-chain-security+3
710 months ago
CVE-2024-38526 preview

CVE-2024-38526

GitHubputget/cve-2024-38526

CVE-2024-38526 - Polyfill Scanner

crawlerinformation-gatheringscripting-automation+3
2 years ago
sage preview

sage

GitHubgendigitalinc/sage

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

ai-securitycode-analysisdefensive-tools+6
31118 days ago
Previous12…16Next