Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
300 results
trivy preview

trivy

GitHubaquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

cloud-infrastructure-securitycloud-securitycode-analysis+14
38.3k
22h 41m ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubjvr2022/cve-2026-31802

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

exploitationsupply-chain-securityvulnerability-analysis+1
16 months ago
github-dev-token-steal-poc preview

github-dev-token-steal-poc

GitHubammaraskar/github-dev-token-steal-poc

Proof-of-concept exploit demonstrating a GitHub OAuth token-stealing vulnerability via crafted developer workflow triggers, enabling unauthorized…

authenticationexploitationsupply-chain-security+2
204 months ago
spring-retry-toolkit preview

spring-retry-toolkit

GitHubnichetoolkit/spring-retry-toolkit

spring retry 1.3.x fix with niche toolkit for CVE-2026-41710

supply-chain-securityvulnerability-analysisweb-security
1 month ago
NodeJS-Tar-Symlink-Exploit-CVE-2026-29786 preview

NodeJS-Tar-Symlink-Exploit-CVE-2026-29786

GitHubrohitberiwala/nodejs-tar-symlink-exploit-cve-2026-29786

Technical analysis and Proof-of-Concept (PoC) for a critical Path Traversal vulnerability via Symlink manipulation in the Node.js 'tar' package…

exploitationsupply-chain-securityvulnerability-analysis+1
17 months ago
snyk-js-jquery-174006 preview
Archived

snyk-js-jquery-174006

GitHubdanielruf/snyk-js-jquery-174006

patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428

code-analysissupply-chain-securityvulnerability-analysis+1
284 years ago
L4J-Vuln-Patch preview
Archived

L4J-Vuln-Patch

GitHubjacobtread/l4j-vuln-patch

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

exploitationmisconfigurationsupply-chain-security+2
54 years ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1827 days ago
secfixes-tracker preview

secfixes-tracker

GitHubaquasecurity/secfixes-tracker

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

devsecopsinformation-gatheringsupply-chain-security+2
83 months ago
advisories preview

advisories

GitHubjustinsteven/advisories

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

cloud-securitycurated-resourceseducation+3
2723 years ago
AuraBorealisApp preview
Archived

AuraBorealisApp

GitHubiqtlabs/auraborealisapp

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

code-analysismalware-analysisstatic-code-analysis+2
204 years ago
vexhub-crawler preview

vexhub-crawler

GitHubaquasecurity/vexhub-crawler

Collect VEX documents and update VEX Hub

crawlerinformation-gatheringsupply-chain-security+3
711 months ago
CVE-2024-38526 preview

CVE-2024-38526

GitHubputget/cve-2024-38526

CVE-2024-38526 - Polyfill Scanner

crawlerinformation-gatheringscripting-automation+3
2 years ago
sage preview

sage

GitHubgendigitalinc/sage

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

ai-securitycode-analysisdefensive-tools+6
31122 days ago
Harden-Windows-Security preview

Harden-Windows-Security

GitHubhotcakex/harden-windows-security

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

configuration-auditingdefensive-toolsencryption-decryption-tools+3
4.8k12h 30m ago
awesome-nodejs-security preview

awesome-nodejs-security

GitHublirantal/awesome-nodejs-security

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

code-analysiscurated-resourceseducation+5
3.0k1 month ago
agent-scan preview

agent-scan

GitHubsnyk/agent-scan

Security scanner for AI agents, MCP servers and agent skills.

ai-securitycode-analysisdynamic-analysis-sandboxing+3
3.1k1 day ago
pip-audit preview

pip-audit

GitHubpypa/pip-audit

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

devsecopssecret-detectionsupply-chain-security+1
1.4k12 days ago
Previous12…17Next