Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
pentest-harness preview

pentest-harness

GitHubs1n6h/pentest-harness

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

ai-securitycommand-and-controlctf+7
407
27 days ago
spectrIDA-Reverse_Engineering_Stack preview

spectrIDA-Reverse_Engineering_Stack

GitHubggfuchsi-oss/spectrida-reverse_engineering_stack

Parallel IDA Pro binary analysis with AI-powered function naming, Neo4j knowledge graph, and phantomrt emulation/hooking/fuzzing engine for automated…

ai-assisted-reversingbinary-analysisctf+8
633 months ago
ai-ctf preview

ai-ctf

GitHubmubix/ai-ctf

Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.

ai-securityctfeducation+6
7317 days ago
linuxprivchecker preview

linuxprivchecker

GitHubsleventyeleven/linuxprivchecker

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

ctfeducationinformation-gathering+3
1.9k5 years ago
pentest-pivoting preview

pentest-pivoting

GitHubt3l3machus/pentest-pivoting

A compact guide to network pivoting for penetration testings / CTF challenges.

ctfcurated-resourceseducation+5
2272 years ago
CVE-2025-11262-Lab preview

CVE-2025-11262-Lab

GitHubrootdirective-sec/cve-2025-11262-lab

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

ctfeducationlabs-practice+3
3 months ago
hacker-profile preview

hacker-profile

GitLabnoraj/hacker-profile

Personal hacker profile page showcasing CTF achievements, cybersecurity projects, and curated resources. Built with Middleman and Gulp for static…

ctfcurated-resourceseducation
120 days ago
CVE-2026-23631 preview

CVE-2026-23631

GitHubhorkimhab/cve-2026-23631

CVE-2026-23631-Draft

ctfeducationexploitation+3
4 months ago
CTFCrackTools preview

CTFCrackTools

GitHub0chencc/ctfcracktools

The next-generation CTF Swiss Army Knife powered by Rust & Tauri. Features a visual node-based workflow and local AI intelligence for extreme…

cryptographyctfeducation+2
2.2k5 months ago
CVE-2026-5718-Lab preview

CVE-2026-5718-Lab

GitHubrootdirective-sec/cve-2026-5718-lab

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

ctfeducationexploitation+3
14 months ago
Windows-Privilege-Escalation-Notes preview

Windows-Privilege-Escalation-Notes

GitHubsaisathvik1/windows-privilege-escalation-notes

My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJ…

ctfeducationexploitation+5
584 years ago
CVE-2026-29000 preview

CVE-2026-29000

GitHublucastran05/cve-2026-29000

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

authenticationctfeducation+3
4 months ago
kasld preview

kasld

GitHubbcoles/kasld

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration,…

binary-exploitationctfexploitation+3
55420h 57m ago
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
8055 months ago
CVE-2026-7465-Lab preview

CVE-2026-7465-Lab

GitHubrootdirective-sec/cve-2026-7465-lab

Local Docker lab for analyzing and reproducing CVE-2026-7465 in Spectra Gutenberg Blocks WordPress plugin. Compares vulnerable vs patched versions…

ctfeducationexploitation+3
4 months ago
CVE-2026-8206-Lab preview

CVE-2026-8206-Lab

GitHubrootdirective-sec/cve-2026-8206-lab

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…

ctfeducationexploitation+3
4 months ago
CVE-2026-8181-Lab preview

CVE-2026-8181-Lab

GitHubrootdirective-sec/cve-2026-8181-lab

Docker lab demonstrating CVE-2026-8181 authentication bypass in Burst Statistics WordPress plugin. Compares vulnerable and patched versions with a…

authenticationctfeducation+5
4 months ago
Metabase_CVE-2021-41277 preview

Metabase_CVE-2021-41277

GitHubvulnmachines/metabase_cve-2021-41277

Exploit for Metabase CVE-2021-41277, a local file inclusion vulnerability in custom GeoJSON map support, allowing unauthorized file access.

ctfcurated-resourceseducation+3
44 years ago
Previous12345Next