Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
PentestingEverything preview

PentestingEverything

GitHubm14r41/pentestingeverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

api-securitycloud-securityctf+9
2.1k
1 day ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 months ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
4 months ago
HTB-Facts-Writeup preview

HTB-Facts-Writeup

GitHubkarimelsheikh1/htb-facts-writeup

HackTheBox Facts machine writeup — CVE-2025-2304, MinIO S3 enumeration, SSH key cracking, and facter privilege escalation.

cloud-securityctfeducation+7
4 months ago
stegbrute preview

stegbrute

GitHubr4ygm/stegbrute

Fast Steganography bruteforce tool written in Rust useful for CTF's

ctfpassword-crackingsteganography
2451 year ago
gtfocli preview

gtfocli

GitHubcmd-tools/gtfocli

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

ctfinformation-gatheringpenetration-testing+1
196 days ago
DVAP preview

DVAP

GitHubsonuoffsec/dvap

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

ai-securityctfeducation+4
292 months ago
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
7584 months ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
9237 months ago
GOATCasino preview

GOATCasino

GitHubnccgroup/goatcasino

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

code-analysisctfeducation+3
1207 years ago
BlockChainSec preview

BlockChainSec

GitHubal1ex/blockchainsec

BlockChain Security

code-analysiscryptographyctf+5
285 years ago
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection preview

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

GitHubhunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

Proof-of-concept exploit for CVE-2026-58116 demonstrating remote code execution in LLaMA-Factory WebUI via trust_remote_code model path injection.…

code-analysisctfeducation+5
2 months ago
Codify-TJNULL-OSCP- preview

Codify-TJNULL-OSCP-

GitHubr3fr4kt/codify-tjnull-oscp-

Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege…

ctfeducationexploitation+5
1 month ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
4 months ago
HTB-Mailing-A-Complete-Walkthrough preview

HTB-Mailing-A-Complete-Walkthrough

GitHubthemursalin/htb-mailing-a-complete-walkthrough

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…

ctfeducationexploitation+8
5 months ago
CVE-2015-3306-Home-Lab preview

CVE-2015-3306-Home-Lab

GitHubnetw0rk7/cve-2015-3306-home-lab

CVE-2015-3306 - ProFTPD - RCE Home Lab setup (Docker) easy to use for Red Teaming or Penetration Testing

ctfeducationexploitation+5
9 months ago
wargame-tarpioka preview

wargame-tarpioka

GitHubm0d0ri205/wargame-tarpioka

YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy

ctfeducationlabs-practice+2
1 year ago
radare2 preview

radare2

GitHubradareorg/radare2

UNIX-like reverse engineering framework and command-line toolset

ai-assisted-reversingandroid-securitybinary-analysis+16
24.8k10h 39m ago
Previous1234Next