Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1051 results
CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough preview

CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough

GitHubbenedictejepu/cve-2024-24945-nginx-rift---tryhackme-lab-walkthrough

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

binary-exploitationctfeducation+5
2 months ago
php_filter_chain_oracle_poc preview

php_filter_chain_oracle_poc

GitHub4xura/php_filter_chain_oracle_poc

PoC scripts to exploit LFR (Local File Read) via PHP filters chain oracle (php://filter), especially for CTF purposes or the exploit of…

ctfexploitationinformation-gathering+3
21 year ago
RsaCtfTool preview

RsaCtfTool

GitHubrsactftool/rsactftool

RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data

cryptographyctfeducation+3
7.1k4 days ago
BadZure preview

BadZure

GitHubmvelazc0/badzure

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

cloud-securityctfeducation+6
52418 days ago
KQL-threat-hunting-queries preview

KQL-threat-hunting-queries

GitHubcyb3rmik3/kql-threat-hunting-queries

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

ctfcurated-resourceseducation+4
7973 months ago
browser-pwn preview

browser-pwn

GitHubm1ghtym0/browser-pwn

An updated collection of resources targeting browser-exploitation.

binary-exploitationctfcurated-resources+4
8305 years ago
GOATCasino preview

GOATCasino

GitHubnccgroup/goatcasino

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

code-analysisctfeducation+3
1207 years ago
ctf-party preview

ctf-party

GitHubnoraj/ctf-party

:triangular_flag_on_post: A CLI tool & library to enhance and speed up script/exploit writing with string conversion/manipulation.

ctfscripting-automationutilities-frameworks
9117 days ago
CVE-2025-62215_Windows_Kernel_PE preview

CVE-2025-62215_Windows_Kernel_PE

GitHubabrewer251/cve-2025-62215_windows_kernel_pe

This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM.…

binary-exploitationctfeducation+3
2010 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
roundcube-cve-2025-49113-lab preview

roundcube-cve-2025-49113-lab

GitHubankitpandey383/roundcube-cve-2025-49113-lab

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

code-analysisctfeducation+7
10 months ago
CVE-2022-21661 preview

CVE-2022-21661

GitHubfauzan-aldi/cve-2022-21661

A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment.

ctfeducationexploitation+3
1 year ago
jwt_tool preview

jwt_tool

GitHubticarpi/jwt_tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

api-securityapi-security-testingcryptography+5
6.8k1 year ago
CVE-2018-15133-Lavel-Expliot preview

CVE-2018-15133-Lavel-Expliot

GitHubnatteesetobol/cve-2018-15133-lavel-expliot

"Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was…

ctfexploitationpenetration-testing+2
4 years ago
Pentest-Bookmarkz preview

Pentest-Bookmarkz

GitHubsofianehamlaoui/pentest-bookmarkz

A collection of useful links for Pentesters

ctfcurated-resourceseducation+9
1801 year ago
CrackMeZ3S-CTF-CrackMe-Tutorial preview

CrackMeZ3S-CTF-CrackMe-Tutorial

GitHubpelock/crackmez3s-ctf-crackme-tutorial

How to write a CrackMe for a CTF competition. Source code, technical explanation, anti-debugging and anti reverse-engineering tricks.

binary-analysisctfeducation+2
473 years ago
CVE-2021-38297-Go-wasm-Replication preview

CVE-2021-38297-Go-wasm-Replication

GitHubparas98/cve-2021-38297-go-wasm-replication

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

binary-exploitationctfeducation+6
2 years ago
CVE-2022-24227-updated preview

CVE-2022-24227-updated

GitHubcyber-wo0dy/cve-2022-24227-updated

CVE-2022-24227 [Updated]: BoltWire v8.00 vulnerable to "Stored Cross-site Scripting (XSS)"

ctfeducationexploitation+3
2 years ago
Previous1…456…59Next