Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1051 results
Heartbleed preview

Heartbleed

GitHubryo-soikutsu/heartbleed

Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for…

ctfeducationexploitation+3
5 months ago
vulnerability-in-Remix-React-Router-CVE-2025-31137- preview

vulnerability-in-Remix-React-Router-CVE-2025-31137-

GitHubpouriam23/vulnerability-in-remix-react-router-cve-2025-31137-

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

ctfeducationexploitation+3
11 year ago
90DaysOfCyberSecurity preview

90DaysOfCyberSecurity

GitHubfarhanashrafdev/90daysofcybersecurity

Structured 90-day cybersecurity study plan with daily tasks covering Network+, Security+, Linux, Python, traffic analysis, cloud security, and…

cloud-securityctfcurated-resources+4
19.3k9 days ago
payloads preview

payloads

GitHubfoospidy/payloads

Git All the Payloads! A collection of web attack payloads.

ctfcurated-resourceseducation+6
4.0k5 years ago
awesome-cybersec preview

awesome-cybersec

GitHubdhotrey/awesome-cybersec

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

ctfcurated-resourceseducation+8
1941 month ago
CICD-Goat-Vapt-Writeup preview

CICD-Goat-Vapt-Writeup

GitHubdheeraj-jayaswal/cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

ctfdevsecopseducation+5
112 days ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
5 months ago
Awesome-Pentest preview

Awesome-Pentest

GitHubal1ex/awesome-pentest

Collection of penetration testing tools

ctfcurated-resourceseducation+6
835 years ago
osx-password-dumper preview

osx-password-dumper

GitHubjeanpeyremesmots/osx-password-dumper

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

ctfpassword-crackingpenetration-testing+2
531 year ago
vulnrepro-benchmark preview

vulnrepro-benchmark

GitHubfarhadalimohammadi-dir/vulnrepro-benchmark

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

ai-securitycode-analysisctf+7
93 months ago
local-llm-ctf preview

local-llm-ctf

GitHubbishopfox/local-llm-ctf

A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow

ai-securityctfeducation+2
192 years ago
React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web preview

React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web

GitHubadityabhatt3010/react2shell-cve-2025-55182-the-deserialization-bug-that-broke-the-web

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

ctfeducationexploitation+8
89 months ago
sudoinjection preview

sudoinjection

GitHubmikivirus0/sudoinjection

Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)

binary-exploitationctfeducation+5
21 year ago
Sandbox-Challenge-Spring4Shell-CVE-2022-22965- preview

Sandbox-Challenge-Spring4Shell-CVE-2022-22965-

GitHubfelisha-elmer/sandbox-challenge-spring4shell-cve-2022-22965-

Step-by-step walkthrough of exploiting CVE-2022-22965 (Spring4Shell) with Metasploit, deploying a C2 listener, and mitigating the vulnerability by…

command-and-controlctfeducation+6
3 months ago
CVE-2024-34070 preview

CVE-2024-34070

GitHubokymi-x/cve-2024-34070

Proof-of-concept exploit for CVE-2024-34070, a stored XSS in Froxlor. Detects vulnerable instances, extracts version, and injects payload to create…

ctfeducationexploitation+3
3 months ago
CVE-2025-46041 preview

CVE-2025-46041

GitHubbinneko/cve-2025-46041

Proof-of-concept for a stored XSS vulnerability in Anchor CMS v0.12.7, demonstrating arbitrary JavaScript execution via the page description field.

ctfeducationpenetration-testing+2
1 year ago
cve-2022-44268 preview

cve-2022-44268

GitHubjkobierczynski/cve-2022-44268
ctfexploitationinformation-gathering+3
1 year ago
binja_sensei preview

binja_sensei

GitHubnccgroup/binja_sensei

A plugin that provides resources for beginners to learn reverse engineering using Binary Ninja. It automatically installs several other plugins, and…

binary-analysisbinary-exploitationctf+4
269 years ago
Previous1…345…59Next