Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
261 results
tailsnitch preview

tailsnitch

GitHubadversis/tailsnitch

A security auditor for Tailscale configurations. Scans your tailnet for misconfigurations, overly permissive access controls, and security best…

cloud-securityconfiguration-auditingdevsecops+4
1.1k
19 days ago
agentic-radar preview

agentic-radar

GitHubsplx-ai/agentic-radar

A security scanner for your LLM agentic workflows

adversarial-attackai-securitydevsecops+5
1.1k9 months ago
huskyCI preview

huskyCI

GitHubglobocom/huskyci

Performing security tests inside your CI

code-analysisdevsecopssecret-detection+2
5952 years ago
sast-scan preview

sast-scan

GitHubshiftleftsecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

cloud-securitycode-analysisconfiguration-auditing+6
8803 years ago
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
7934 months ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5576 months ago
legitify preview

legitify

GitHublegit-labs/legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

cloud-securityconfiguration-auditingdevsecops+3
8871 year ago
apex preview

apex

GitHubpensarai/apex

AI-powered offensive security testing using autonomous agents, directly in your terminal.

ai-securitycloud-securitydevsecops+7
3117 days ago
yatas preview

yatas

GitHubpadok-team/yatas

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
3434 months ago
ghostbuster preview

ghostbuster

GitHubassetnote/ghostbuster

Eliminate dangling elastic IPs by performing analysis on your resources within all your AWS accounts.

cloud-securitydns-analysisreconnaissance+2
2792 years ago
docker-hacklab preview

docker-hacklab

GitHubjohackim/docker-hacklab

My personal hacklab, create your own.

curated-resourceseducationexploit-frameworks+7
3325 months ago
Egyscan preview

Egyscan

GitHubdragonked2/egyscan

Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

crawlerinformation-gatheringpenetration-testing+4
3031 month ago
ssh-auditor preview

ssh-auditor

GitHubncsa/ssh-auditor

The best way to scan for weak ssh passwords on your network

network-securitypassword-attacksvulnerability-scanners
6195 years ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

ai-securitycommand-and-controldata-exfiltration+7
3743 months ago
log4j_checker_beta preview

log4j_checker_beta

GitHubrubo77/log4j_checker_beta

a fast check, if your server could be vulnerable to CVE-2021-44228

code-analysisdynamic-analysis-sandboxingincident-response+3
2474 years ago
fix-react2shell-next preview

fix-react2shell-next

GitHubvercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

code-analysisdevsecopsscripting-automation+3
4019 months ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

ai-securitycloud-securitycommand-and-control+7
21611h 15m ago
scripts-and-tools preview

scripts-and-tools

GitHubphxbandit/scripts-and-tools

Scripts and utilities to help your hacking needs

dns-analysisexploitationforensics+6
886 months ago
Previous123…15Next