Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
589 results
Agent-Security-Regression-Harness preview

Agent-Security-Regression-Harness

GitHubowasp/agent-security-regression-harness

Executable security regression testing for agentic applications and MCP-integrated systems.

ai-securityapi-security-testingcode-analysis+4
52
2 months ago
Security-Champions preview

Security-Champions

GitHubowasp/security-champions

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

curated-resourceseducationlearning-paths-courses+2
192 months ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

ai-securitycloud-securityeducation+5
22 months ago
wp2shell-lab preview

wp2shell-lab

GitHubananay/wp2shell-lab

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

api-security-testingcode-analysiseducation+3
2 months ago
CVE-2026-60206 preview

CVE-2026-60206

GitHubdebajyoti0-0/cve-2026-60206

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

authenticationexploitationpenetration-testing+2
12 months ago
crucible preview

crucible

GitHubcrucible-security/crucible

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

ai-securitydevsecopseducation+3
502 months ago
awesome-cybersec preview

awesome-cybersec

GitHubdhotrey/awesome-cybersec

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

ctfcurated-resourceseducation+8
1952 months ago
morf preview

morf

GitHubamrudesh1/morf

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

android-securityios-securitymobile-security+4
862 months ago
CVE-2026-46592 preview

CVE-2026-46592

GitHuboscerd/cve-2026-46592

Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a…

api-security-testingeducationexploitation+3
2 months ago
abdal-cve-2026-63030 preview

abdal-cve-2026-63030

GitHubebrasha/abdal-cve-2026-63030

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

api-security-testinginformation-gatheringpenetration-testing+2
32 months ago
OWASP-MCP-Threat-Modeling preview

OWASP-MCP-Threat-Modeling

GitHubowasp/owasp-mcp-threat-modeling

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

curated-resourceseducationthreat-intelligence+1
12 months ago
Audio-Video-Communications-Top-10 preview

Audio-Video-Communications-Top-10

GitHubowasp/audio-video-communications-top-10

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

curated-resourceseducationnetwork-security+3
2 months ago
cyclonedx-cli preview

cyclonedx-cli

GitHubcyclonedx/cyclonedx-cli

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

cryptographydefensive-toolsdevsecops+2
5452 months ago
CVE-2026-49099 preview

CVE-2026-49099

GitHuboscerd/cve-2026-49099

PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and…

api-security-testingeducationexploitation+3
2 months ago
CVE-2026-48206 preview

CVE-2026-48206

GitHuboscerd/cve-2026-48206

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

api-security-testingeducationexploitation+3
2 months ago
bordair-multimodal preview

bordair-multimodal

GitHubjosh-blythe/bordair-multimodal

Open-source cross-modal and multimodal prompt injection test suite. 250,000+ attack payloads across text, image, document, and audio modalities.…

adversarial-attackai-securitycurated-resources+5
762 months ago
mcpshield preview

mcpshield

GitHubcsinexus/mcpshield

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

api-security-testingcode-analysiscommand-and-control+3
2 months ago
SBOM-VEX-Taint-Analysis preview

SBOM-VEX-Taint-Analysis

GitHubowasp/sbom-vex-taint-analysis

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

ai-securitycurated-resourceseducation+3
42 months ago
Previous1…101112…33Next