Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
287 results
zephyr preview

zephyr

GitHubzephyrproject-rtos/zephyr

Primary Git Repository for the Zephyr Project. Zephyr is a new generation, scalable, optimized, secure RTOS for multiple hardware architectures.

bluetooth-securitycurated-resourceseducation+4
16.6k
3 days ago
reposcanner preview

reposcanner

GitHubdionach/reposcanner

Python script to scan Git repos for interesting strings

code-analysisdevsecopsinformation-gathering+1
1606 years ago
gitpwnd preview

gitpwnd

GitHubnccgroup/gitpwnd

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

command-and-controlpenetration-testingpersistence-mechanisms+3
1475 years ago
sbomlyze preview

sbomlyze

GitHubrezmoss/sbomlyze

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

configuration-auditingdevsecopssecret-detection+5
2425 days ago
CVE-2019-10392 preview

CVE-2019-10392

GitHubjas502n/cve-2019-10392

Authenticated remote code execution exploit for Jenkins Git Client Plugin 2.8.2 via Jackson deserialization vulnerability (CVE-2019-10392).

code-analysisexploitationpenetration-testing+2
217 years ago
GitLeaks preview

GitLeaks

GitLabniclas-zone/ci/gitleaks

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

code-analysisdevsecopssecret-detection+1
12 months ago
aqua-checksums preview

aqua-checksums

GitHubknqyf263/aqua-checksums

Monitors cryptographic integrity of container images, releases, and Git tags for supply chain security, verifying Sigstore cosign signatures with…

container-securitydefensive-toolsdevsecops+2
5 months ago
git-secrets-scan preview

git-secrets-scan

Bitbucketatlassian/git-secrets-scan

Scans Git repositories for hardcoded secrets, keys, and passwords using Gitleaks, integrating security into Bitbucket Pipelines with Code Insights…

cloud-securityconfiguration-auditingdevsecops+3
1 year ago
jenkinsci__git-client-plugin_CVE-2019-10392_2-8-4 preview

jenkinsci__git-client-plugin_CVE-2019-10392_2-8-4

GitHubshoucheng3/jenkinsci__git-client-plugin_cve-2019-10392_2-8-4

Jenkins plugin providing Git APIs for automated repository operations including fetch, checkout, merge, and tag, with support for credential-based…

authenticationcode-analysisdevsecops+2
1 year ago
CVE-2020-27955-LFS preview

CVE-2020-27955-LFS

GitHubmarsable/cve-2020-27955-lfs

RCE exploit for CVE-2020-27955 targeting Git LFS on Windows, with .bat and PowerShell payloads for testing Git, GitHub CLI, VS Code, and other tools.

binary-exploitationexploitationpayload-development+3
5 years ago
cve-2021-21300 preview

cve-2021-21300

GitHubetocheney/cve-2021-21300

Proof-of-concept exploit for CVE-2021-21300, demonstrating exploitation of a Git vulnerability for remote code execution.

exploitationvulnerability-analysis
5 years ago
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
304 months ago
CVE-2026-3854-lab preview

CVE-2026-3854-lab

GitHubroyaleybovich/cve-2026-3854-lab

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

ctfeducationexploitation+4
91 month ago
prefect-cve-2026-5366 preview

prefect-cve-2026-5366

GitHubrenat0z3r0/prefect-cve-2026-5366

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

code-analysiseducationexploitation+3
3 months ago
cve-2024-32002-poc preview

cve-2024-32002-poc

GitHubjoaoleonello/cve-2024-32002-poc

Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.

educationexploitationpenetration-testing+3
11 months ago
CVE-2017-1000117 preview

CVE-2017-1000117

GitHubsiling2017/cve-2017-1000117

Proof-of-concept exploit for CVE-2017-1000117 (Git SSH command injection) that writes command output to a web-accessible file. Part of VulApps…

educationexploitationlabs-practice+2
9 years ago
running-CVE-2024-32002-locally-for-tesing preview

running-CVE-2024-32002-locally-for-tesing

GitHubchriswalker11/running-cve-2024-32002-locally-for-tesing

Local reproduction environment for CVE-2024-32002 Git RCE exploit using Gitea, with custom payload injection via post-checkout hooks and submodule…

educationexploitationlabs-practice+3
2 years ago
CVE-2024-32002 preview

CVE-2024-32002

GitHubflojboj/cve-2024-32002

Educational exploit script for CVE-2024-32002 (Git RCE) with automated setup, designed for CTF environments and security training.

ctfeducationexploitation+2
2 years ago
Previous123…16Next