Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
10 results
payloads preview

payloads

GitHubfoospidy/payloads

Git All the Payloads! A collection of web attack payloads.

ctfcurated-resourceseducation+6
4.0k5 years ago
LFI-Destruction preview

LFI-Destruction

GitHubrevshellxd/lfi-destruction

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

ctfeducationexploitation+8
47 months ago
etherblob-explorer preview

etherblob-explorer

GitHublitneet64/etherblob-explorer

Search and extract blob files on the Ethereum Blockchain network

ctfdata-recoveryforensics+2
435 years ago
OFFPORT_KILLER preview

OFFPORT_KILLER

GitHubth3xace/offport_killer

This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

ctfinformation-gatheringnetwork-security+3
506 years ago
Resources-for-Application-Security preview

Resources-for-Application-Security

GitHubsecurity-prince/resources-for-application-security

Some good resources for getting started with application security

ctfcurated-resourcesdynamic-analysis-sandboxing+6
1496 years ago
CVE-2025-49113-Roundcube-RCE preview

CVE-2025-49113-Roundcube-RCE

GitHubrippsec/cve-2025-49113-roundcube-rce

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

code-analysisctfexploitation+4
5 months ago
fas-judgement-oss preview

fas-judgement-oss

GitHubfallen-angel-systems/fas-judgement-oss

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

adversarial-attackai-securityctf+8
136 months ago
awesome-ctf-resources preview

awesome-ctf-resources

GitHubdevploit/awesome-ctf-resources

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

cryptographyctfcurated-resources+6
80511 days ago
cve-2026-54316-lab preview

cve-2026-54316-lab

GitHubinertfluid/cve-2026-54316-lab

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

ctfdata-exfiltrationeducation+5
13 months ago
CVE-2026-44881_exploit preview

CVE-2026-44881_exploit

GitHub0xdak/cve-2026-44881_exploit

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

cloud-securitycontainer-securityctf+7
3 months ago