Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
terrier preview

terrier

GitHubheroku/terrier

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

container-securityhash-analysissupply-chain-security+1
228
4 months ago
kubescape preview

kubescape

GitHubkubescape/kubescape

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
11.8k2h 14m ago
checkov preview

checkov

GitHubbridgecrewio/checkov

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

cloud-infrastructure-securitycloud-securitycode-analysis+12
9.1k1 day ago
syft preview

syft

GitHubanchore/syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

container-escapecontainer-securitydevsecops+3
9.7k3h 37m ago
CVE-2024-1086 preview

CVE-2024-1086

GitHubnotselwyn/cve-2024-1086

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including…

binary-exploitationeducationexploitation+4
2.5k2 years ago
forticrack preview

forticrack

GitHubbishopfox/forticrack

Decrypt encrypted Fortienet FortiOS firmware images

cryptographyembedded-systems-securityencryption-decryption-tools+3
1663 years ago
divd-2021-00038--log4j-scanner preview

divd-2021-00038--log4j-scanner

GitHubdtact/divd-2021-00038--log4j-scanner

Recursive vulnerability scanner for Log4j CVEs in archives and Docker images. Detects JndiLookup.class and vulnerable versions via SHA256 hashes,…

cloud-securitycontainer-securitydevsecops+3
464 years ago
forticrack_v8 preview

forticrack_v8

GitHubhacefresko/forticrack_v8

Decrypt and extract FortiOS 8.0.0 firmware images.

embedded-systems-securityencryption-decryption-toolsfirmware-analysis+3
293 months ago
capture-the-flag preview

capture-the-flag

GitHubctf-o-matic/capture-the-flag

Helper scripts to remaster Linux Live CD images for the purpose of creating ready to use security wargames with pre-installed vulnerabilities to…

ctfeducationexploitation+3
527 years ago
CVE-2022-44268 preview

CVE-2022-44268

GitHubkljunowsky/cve-2022-44268

Proof-of-concept exploit for CVE-2022-44268 enabling arbitrary file read via poisoned PNG images uploaded to vulnerable ImageMagick instances.…

exploitationinformation-gatheringpayload-generation+3
262 years ago
Cable-modems preview

Cable-modems

GitHubebux/cable-modems

Black-box security evaluation of five ISP cable modem/router gateways, analyzing firmware images and documenting 35+ vulnerabilities including…

embedded-systems-securityexploitationfirmware-analysis+5
2510 years ago
SecFlow preview

SecFlow

GitHubaradhyacp/secflow

AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates…

ai-securityforensicsincident-response+6
227 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubblueteamsteve/cve-2021-41773

Vulnerable docker images for CVE-2021-41773

container-securityeducationexploitation+3
235 years ago
CVE-2026-27771 preview

CVE-2026-27771

GitHubportbuster1337/cve-2026-27771

CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

authentication-authorizationcontainer-securityeducation+5
204 months ago
MMSkillRisk preview

MMSkillRisk

GitHubkaill-jlq/mmskillrisk

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

adversarial-attackai-securitydata-exfiltration+7
69 days ago
test_avb_key preview

test_avb_key

GitHubnccgroup/test_avb_key

Python utility to check if Android verified boot images (vbmeta) are signed with publicly known test keys, identifying misconfigurations in release…

android-securitycryptographyfirmware-analysis+3
82 years ago
CVE-2021-1931-BBRY-KEY2 preview

CVE-2021-1931-BBRY-KEY2

GitHubfakeshell/cve-2021-1931-bbry-key2

proof of concept CVE-2021-1931 exploit for the blackberry key2 (le) that allows to flash unsigned images temporarily

android-securityembedded-systems-securityexploitation+2
81 year ago
log4j-docker preview

log4j-docker

GitHubankur-katiyar/log4j-docker

Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)

cloud-securitycontainer-securityeducation+3
54 years ago
Previous12345Next