Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
dcipher-cli preview

dcipher-cli

GitHubk4m4/dcipher-cli

🔓Crack hashes using online rainbow & lookup table attack services, right from your terminal.

cryptographyctfhash-analysis+1
233
5 years ago
cloudfoxable preview

cloudfoxable

GitHubbishopfox/cloudfoxable

Create your own vulnerable by design AWS penetration testing playground

cloud-infrastructure-securitycloud-securityctf+3
4724 months ago
webvm preview

webvm

GitHubleaningtech/webvm

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

cloud-securityctfdevsecops+3
17.4k6 days ago
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
51412 days ago
dcipher preview

dcipher

GitHubk4m4/dcipher

Decipher hashes using online rainbow & lookup table attack services.

cryptographyctfhash-analysis+1
1525 years ago
DynastyPersist preview

DynastyPersist

GitHubtrevohack/dynastypersist

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

ctfpenetration-testingpersistence-mechanisms+3
16211 months ago
OFFPORT_KILLER preview

OFFPORT_KILLER

GitHubth3xace/offport_killer

This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

ctfinformation-gatheringnetwork-security+3
505 years ago
TryHackMe-CVE-2022-26923 preview

TryHackMe-CVE-2022-26923

GitHubr1skkam/tryhackme-cve-2022-26923

Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services

ctfeducationexploitation+2
64 years ago
CVE-2026-5718-Lab preview

CVE-2026-5718-Lab

GitHubrootdirective-sec/cve-2026-5718-lab

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

ctfeducationexploitation+3
13 months ago
cve-2011-2553 preview

cve-2011-2553

GitHubcarlosrpastrana/cve-2011-2553

Bash exploit for CVE-2011-2553 enabling remote code execution and privilege escalation on vulnerable FTP services via a special character in the USER…

ctfeducationexploitation+3
111 months ago
CVE-2026-3844-Lab preview

CVE-2026-3844-Lab

GitHubrootdirective-sec/cve-2026-3844-lab

Local Docker lab for reproducing CVE-2026-3844, an unauthenticated arbitrary file upload to RCE in the WordPress Breeze Cache plugin. Compares…

ctfeducationexploitation+3
3 months ago
autoenum preview

autoenum

GitHubgr1mmie/autoenum

Automatic Service Enumeration Script

ctfinformation-gatheringnetwork-mapping+4
2303 years ago
CVE-2022-26923 preview

CVE-2022-26923

GitHubnefhara/cve-2022-26923

Automated CVE-2022-26923 Exploitation (Certifried)

authenticationctfeducation+6
3 months ago
CVE-2025-29927-Proof-of-Concept preview

CVE-2025-29927-Proof-of-Concept

GitHubsi-ni/cve-2025-29927-proof-of-concept

Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability

command-and-controlctfeducation+4
7 months ago
CVE-2017-7269 preview

CVE-2017-7269

GitHubvanishedpeople/cve-2017-7269

Python proof-of-concept for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution on Windows Server 2003 R2.

ctfexploitationpenetration-testing+2
1 year ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

cloud-securityctfcurated-resources+10
27.1k1 month ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
11.5k1 month ago
90DaysOfCyberSecurity preview

90DaysOfCyberSecurity

GitHubfarhanashrafdev/90daysofcybersecurity

Structured 90-day cybersecurity study plan with daily tasks covering Network+, Security+, Linux, Python, traffic analysis, cloud security, and…

cloud-securityctfcurated-resources+4
18.9k9 months ago
Previous123Next