Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k
3 days ago
Flutter-Reverse-Engineering-Labs preview

Flutter-Reverse-Engineering-Labs

GitHubbrnpl/flutter-reverse-engineering-labs

Hands-on challenges for learning how to reverse engineer Flutter applications.

android-securitybinary-analysisctf+6
5826 days ago
CrackMeZ3S-CTF-CrackMe-Tutorial preview

CrackMeZ3S-CTF-CrackMe-Tutorial

GitHubpelock/crackmez3s-ctf-crackme-tutorial

How to write a CrackMe for a CTF competition. Source code, technical explanation, anti-debugging and anti reverse-engineering tricks.

binary-analysisctfeducation+2
473 years ago
oasis preview

oasis

GitHubkryptsec/oasis

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

ai-securityctfeducation+6
2921 days ago
ai-email-threat-research preview

ai-email-threat-research

GitHubscottalt/ai-email-threat-research

A cybersecurity research game measuring how humans detect AI-generated phishing emails. Built as a retro terminal experience.

ai-securityctfeducation+4
83 months ago
Digital-Signature-Forgery-Attack preview

Digital-Signature-Forgery-Attack

GitHubdemining/digital-signature-forgery-attack

How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX

cryptographyctfcurated-resources+3
41 year ago
CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough preview

CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough

GitHubbenedictejepu/cve-2024-24945-nginx-rift---tryhackme-lab-walkthrough

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

binary-exploitationctfeducation+5
2 months ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
5 months ago
CVE-2019-18634-writeup preview

CVE-2019-18634-writeup

GitHubdevteam6rabbit/cve-2019-18634-writeup

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

binary-exploitationctfeducation+4
8 months ago
the-book-of-secret-knowledge preview

the-book-of-secret-knowledge

GitHubtrimstray/the-book-of-secret-knowledge

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

ctfcurated-resourceseducation+8
243.3k1 year ago
screenpipe preview

screenpipe

GitHubscreenpipe/screenpipe

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

ctfcurated-resourceseducation+8
21.5k0 days ago
stego-toolkit preview

stego-toolkit

GitHubdominicbreuker/stego-toolkit

Collection of steganography tools - helps with CTF challenges

ctfeducationforensics+2
2.7k6 years ago
BoxPwnr preview

BoxPwnr

GitHub0ca/boxpwnr

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

ai-securityctfeducation+8
4501 month ago
vucsa preview

vucsa

GitHubwarxim/vucsa

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

binary-exploitationctfeducation+3
1023 years ago
covertchannels-steganography preview

covertchannels-steganography

GitHubmindcrypt/covertchannels-steganography

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

ctfcurated-resourcesdata-exfiltration+6
1064 years ago
Basileak preview

Basileak

GitHubowasp/basileak

Intentionally vulnerable LLM

ai-securityctfeducation+6
2819 days ago
tryhackme-monikerlink-writeup preview

tryhackme-monikerlink-writeup

GitHubomarmahmoud1024/tryhackme-monikerlink-writeup

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

ctfeducationexploitation+4
1 month ago
Next.js-Middleware-Bypass-CVE-2025-29927- preview

Next.js-Middleware-Bypass-CVE-2025-29927-

GitHubpouriam23/next.js-middleware-bypass-cve-2025-29927-

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

ctfeducationlabs-practice+3
21 year ago
Previous12Next