Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
log4j-log4shell-affected preview

log4j-log4shell-affected

GitHubauthomize/log4j-log4shell-affected

Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security…

curated-resourceseducationincident-response+3
52
4 years ago
Magento-APSB22-48-Security-Patches preview

Magento-APSB22-48-Security-Patches

GitHubemicoecommerce/magento-apsb22-48-security-patches

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

code-analysismisconfigurationstatic-analysis+3
373 years ago
vercel-april2026-incident-response preview

vercel-april2026-incident-response

GitHubopensourcemalware/vercel-april2026-incident-response

This is an incident response playbook we created for the Vercel April 2026 compromise

cloud-securitydigital-forensicsincident-response+3
324 months ago
AI-SPM preview

AI-SPM

GitHubdshapi/ai-spm

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

ai-securitycloud-securitymisconfiguration+3
123 months ago
CVE-2024-3094_xz_check preview

CVE-2024-3094_xz_check

GitHubhackerhermanos/cve-2024-3094_xz_check

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…

educationscripting-automationsupply-chain-security+2
92 years ago
Supply-Chain preview

Supply-Chain

GitLabtoxicbishop/supply-chain

A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical…

curated-resourceseducationlearning-paths-courses+2
12 months ago
jackson preview

jackson

GitHubsassoftware/jackson

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…

code-analysisgeneral-purpose-utilitiesstatic-analysis+2
14 months ago
cve-2018-6574-exploit preview

cve-2018-6574-exploit

GitHubzerbaliy3v/cve-2018-6574-exploit

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

exploitationpayload-generationsupply-chain-security+2
2 years ago
CVE-2023-26136 preview

CVE-2023-26136

GitHubmorrisel/cve-2023-26136

This repository contains a solution for the CVE-2023-26136 vulnerability.

code-analysiseducationpapers-research+3
1 year ago
go-get-RCE preview

go-get-RCE

GitHubsaptaktdk/go-get-rce

This is the exploit of CVE-2018-6574: go get RCE

exploitationpayload-generationpenetration-testing+2
1 year ago
Linux---Security---Detect-and-Mitigate-CVE-2024-3094 preview

Linux---Security---Detect-and-Mitigate-CVE-2024-3094

GitHublaxmikumari615/linux---security---detect-and-mitigate-cve-2024-3094

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only…

educationincident-responsesupply-chain-security+2
1 year ago
CVE-2023-37478_npm_vs_pnpm preview

CVE-2023-37478_npm_vs_pnpm

GitHubtrevorgkann/cve-2023-37478_npm_vs_pnpm

CVE-2023-37478 showcases how a difference in npm and pnpm install packages that could be exploited by a well crafted tar.gz packge. This repo shows a…

educationexploitationlabs-practice+3
2 years ago
L4J-Vuln-Patch preview
Archived

L4J-Vuln-Patch

GitHubjacobtread/l4j-vuln-patch

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

exploitationmisconfigurationsupply-chain-security+2
54 years ago
trivy-action preview

trivy-action

GitHubaquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

cloud-securitycode-analysiscontainer-security+5
1.4k19 days ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k1 month ago
Docker-Security preview

Docker-Security

GitHubowasp/docker-security

Getting a handle on container security

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
6862 years ago
git_rce preview

git_rce

GitHubamalmurali47/git_rce

Exploit PoC for CVE-2024-32002

educationexploitationpayload-development+3
5332 years ago
hijagger preview

hijagger

GitHubfirefart/hijagger

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

dns-analysisosintreconnaissance+3
3063 days ago
Previous12…8Next