Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1089 results
enum4linux-ng preview

enum4linux-ng

GitHubcddmp/enum4linux-ng

A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security…

ctfinformation-gatheringnetwork-security+2
1.7k
7 months ago
challenge_repo preview

challenge_repo

GitHubquevatech/challenge_repo

Structured challenge repository offering bounties for breaking a neural-network-based random number generator validated against NIST SP 800-22 and SP…

cryptographyctfeducation+2
5 months ago
ROPgadget preview

ROPgadget

GitHubjonathansalwan/ropgadget

Search for ROP gadgets in ELF, PE, Mach-O, and Raw binaries across x86, ARM, MIPS, and RISC-V architectures. Supports automated ROP chain generation…

binary-analysisbinary-exploitationctf+3
4.5k3 months ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k3 months ago
CVE-2024-28397-Exploit-Automation preview

CVE-2024-28397-Exploit-Automation

GitHubl1337xi/cve-2024-28397-exploit-automation

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

ctfeducationexploitation+3
210 months ago
ImageMagick-lfi-poc preview

ImageMagick-lfi-poc

GitHubfanbyprinciple/imagemagick-lfi-poc

Proof-of-concept exploit for CVE-2022-44268 enabling arbitrary file read via crafted PNG images processed by ImageMagick. Includes generation and…

ctfexploitationinformation-gathering+3
13 years ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
5 months ago
mimosa preview

mimosa

GitHubowasp/mimosa

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

ctfeducationlabs-practice+3
3 years ago
demo-CVE-2021-29447-lezione preview

demo-CVE-2021-29447-lezione

GitHubspecializzazione-cyber-security/demo-cve-2021-29447-lezione

Proof-of-concept exploit for CVE-2021-29447, an authenticated XXE vulnerability in WordPress 5.6-5.7. Includes lab setup, malicious WAV generation,…

ctfeducationexploitation+3
1 year ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubrahul-securify/react2shell-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 demonstrating remote code execution in Next.js via prototype pollution. Includes a pre-configured…

ctfeducationexploitation+3
10 months ago
CyberStrikeAI preview

CyberStrikeAI

GitHubed1s0nz/cyberstrikeai

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

ai-securitybinary-analysiscloud-security+9
7.5k0 days ago
hacker-profile preview

hacker-profile

GitLabnoraj/hacker-profile

Personal hacker profile page showcasing CTF achievements, cybersecurity projects, and curated resources. Built with Middleman and Gulp for static…

ctfcurated-resourceseducation
123 days ago
CVE-2022-44268-pilgrimage preview

CVE-2022-44268-pilgrimage

GitHubkatseyres2/cve-2022-44268-pilgrimage

Automated proof-of-concept exploit for CVE-2022-44268 (ImageMagick arbitrary file read) with PNG payload generation, designed for CTF challenges and…

ctfexploitationpenetration-testing+2
1 year ago
vulnrepro-benchmark preview

vulnrepro-benchmark

GitHubfarhadalimohammadi-dir/vulnrepro-benchmark

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

ai-securitycode-analysisctf+7
94 months ago
cve-2025-29927 preview

cve-2025-29927

GitHubgokul-krishnan-v-r/cve-2025-29927

Next.js and the corrupt middleware...TRY TO HACK IT..!

ctfeducationlabs-practice+3
1 year ago
CVE-2023-33733-Exploit-PoC preview

CVE-2023-33733-Exploit-PoC

GitHubl41kaa/cve-2023-33733-exploit-poc

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

ctfexploitationpayload-generation+3
32 years ago
CVE-2022-25765 preview

CVE-2022-25765

GitHubinnocentx0/cve-2022-25765

Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.

command-and-controlctfeducation+4
1 month ago
Variatype.htb-CVE-2025-66034 preview

Variatype.htb-CVE-2025-66034

GitHubliquid1998/variatype.htb-cve-2025-66034

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

ctfexploitationpayload-generation+3
26 months ago
Previous12…61Next