Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k
25 days ago
cai preview

cai

GitHubaliasrobotics/cai

Cybersecurity AI (CAI), the framework for AI Security

ai-securityctfeducation+8
9.8k20 days ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.8k15 days ago
SSRFmap preview

SSRFmap

GitHubswisskyrepo/ssrfmap

Automatic SSRF fuzzer and exploitation tool

ctfexploitationfuzzing+4
3.6k1 month ago
CVE-2026-63030-wp2r00t preview

CVE-2026-63030-wp2r00t

GitHubj4ck3lsyn-gen2/cve-2026-63030-wp2r00t

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

ctfeducationexploitation+5
61 month ago
AllAboutBugBounty preview

AllAboutBugBounty

GitHubdaffainfo/allaboutbugbounty

All about bug bounty (bypasses, payloads, and etc)

ctfcurated-resourceseducation+7
6.9k3 years ago
Damn-Vulnerable-GraphQL-Application preview

Damn-Vulnerable-GraphQL-Application

GitHubdolevf/damn-vulnerable-graphql-application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

api-securityapi-security-testingctf+5
1.7k1 year ago
CVE-2026-42945-POC preview

CVE-2026-42945-POC

GitHubcipherspy/cve-2026-42945-poc

exploit for CVE-2026-42945

binary-exploitationcommand-and-controlctf+7
624 months ago
THM-Vulnerability_Capstone-CVE-2018-16763 preview
Archived

THM-Vulnerability_Capstone-CVE-2018-16763

GitHubwizardy0ga/thm-vulnerability_capstone-cve-2018-16763

A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.

ctfeducationexploitation+5
4 years ago
bug-reaper preview

bug-reaper

GitHubshaniidev/bug-reaper

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

api-security-testingctfeducation+8
716 months ago
AutoPwn-Titanic.htb preview

AutoPwn-Titanic.htb

GitHubmaikneysm/autopwn-titanic.htb

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

ctfexploitationinformation-gathering+5
1 year ago
TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation preview

TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation

GitHubthreatradarai/trai-001-critical-rce-vulnerability-in-apache-parquet-cve-2025-30065-simulation

A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked…

ctfeducationexploitation+3
11 year ago
cve-lfi-lab preview

cve-lfi-lab

GitHubthecyberfairy/cve-lfi-lab

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

ctfeducationincident-response+5
1 year ago
ReactOOPS-WriteUp preview

ReactOOPS-WriteUp

GitHubthestingr/reactoops-writeup

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

code-analysisctfeducation+8
79 months ago
CrushFTP-auth-bypass-CVE-2025-31161 preview

CrushFTP-auth-bypass-CVE-2025-31161

GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

authentication-authorizationcommand-and-controlctf+7
11 months ago
vucsa preview

vucsa

GitHubwarxim/vucsa

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

binary-exploitationctfeducation+3
1023 years ago
firefox-rce-nssmil preview

firefox-rce-nssmil

GitHubsoham23/firefox-rce-nssmil

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

binary-exploitationctfeducation+3
12 months ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
4 months ago
Previous12Next