Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
CVE-2025-3248 preview

CVE-2025-3248

GitHubgraysignal/cve-2025-3248

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

exploitationpenetration-testingvulnerability-analysis+3
1
1 year ago
CVE-2026-63077 preview

CVE-2026-63077

GitHubanggatechi/cve-2026-63077

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…

exploitationpayload-developmentpenetration-testing+2
12 days ago
CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field preview

CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field

GitHubtheopaid/cve-2026-66421-openclaw-dashboard-stored-xss-via-lastmessage-session-field

Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

ai-securityapi-securityexploitation+3
18 days ago
scenester preview

scenester

GitHubnccgroup/scenester

A tool to visually snapshot a website by supplying multiple user-agent. Designed to aid in discovery of different entry points into an application.

information-gatheringosintpenetration-testing+2
3110 years ago
CVE-2025-12189 preview

CVE-2025-12189

GitHubd0n601/cve-2025-12189

Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.10.1321 - Cross-Site Request Forgery to…

exploitationpayload-generationpenetration-testing+3
9 months ago
PHP-8.1.0-dev-Backdoor preview

PHP-8.1.0-dev-Backdoor

GitHubk3ystr0k3r/php-8.1.0-dev-backdoor

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

exploitationpayload-developmentsupply-chain-security+3
11 month ago
rails-forensics-CVE-2026-66066 preview

rails-forensics-CVE-2026-66066

GitHubrails/rails-forensics-cve-2026-66066

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

data-exfiltrationdigital-forensicseducation+3
2520 days ago
rails-activestorage-vips-audit preview

rails-activestorage-vips-audit

GitHubpaveg/rails-activestorage-vips-audit

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

configuration-auditingdevsecopseducation+3
22 days ago
clawshield-public preview

clawshield-public

GitHubsleuthco/clawshield-public

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

ai-securityapi-securitydefensive-tools+6
1305 months ago
Manipulating-Web-Agents preview

Manipulating-Web-Agents

GitHubsej2020/manipulating-web-agents
adversarial-attackai-securityeducation+3
61 year ago
AWE preview

AWE

GitHubstuxlabs/awe

adaptive agents for dynamic web penetration testing

dynamic-analysis-sandboxingeducationpapers-research+4
215 months ago
CTFTiny preview

CTFTiny

GitHubnyu-llm-ctf/ctftiny

Official repository for CTFTiny

ai-securitybinary-exploitationcryptography+8
185 months ago
CVE-2020-5148 preview

CVE-2020-5148

GitHubl0lsec/cve-2020-5148

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

authenticationexploitationinformation-gathering+6
26 days ago
airecon preview

airecon

GitHubpikpikcu/airecon

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

ai-securityeducationexploitation+6
9643 months ago
apex preview

apex

GitHubpensarai/apex

AI-powered offensive security testing using autonomous agents, directly in your terminal.

ai-securitycloud-securitydevsecops+7
3032 days ago
faraday_agent_dispatcher preview

faraday_agent_dispatcher

GitHubinfobyte/faraday_agent_dispatcher

Faraday Agent Dispatcher launches any security tools and send results to Faradaysec Platform.

cloud-securitydevsecopsinformation-gathering+5
486 months ago
octohook preview

octohook

GitHubdsnezhkov/octohook

Git Web Hook Tunnel for C2

command-and-controlpayload-developmentpenetration-testing+2
282 years ago
pd-agent preview

pd-agent

GitHubprojectdiscovery/pd-agent

ProjectDiscovery Cloud - Agent

cloud-securitycontainer-securitydns-analysis+6
132 months ago
Previous1234Next