Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
60 results
Why-so-Serious-SAM preview

Why-so-Serious-SAM

GitHubp1rat3r00t/why-so-serious-sam

PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

ctfeducationexploitation+6
1 year ago
xeca preview

xeca

GitHubpostrequest/xeca

PowerShell payload generator

command-and-controlctfexploitation+6
1204 years ago
Security-Datasets preview

Security-Datasets

GitHubotrf/security-datasets

Re-play Security Events

ctfcurated-resourcesdigital-forensics+4
1.8k2 years ago
mysqli preview

mysqli

GitHubrgkue/mysqli

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

ctfeducationpassword-cracking+3
2 months ago
f8x preview

f8x

GitHubffffffff0x/f8x

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

cloud-securityctfdevsecops+7
2.2k26 days ago
cnappgoat preview

cnappgoat

GitHubtenable/cnappgoat

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

cloud-infrastructure-securitycloud-securityctf+5
2962 years ago
Ciphey preview

Ciphey

GitHubbee-san/ciphey

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

cryptographyctfeducation+2
21.6k2 days ago
POC_react2shell_CVE-2025-55182 preview

POC_react2shell_CVE-2025-55182

GitHubnkwenti-severian-ndongtsop/poc_react2shell_cve-2025-55182
ctfeducationexploitation+4
28 months ago
cs50-cyber-paloalto-oauth preview

cs50-cyber-paloalto-oauth

GitHubyafiah-darwesh/cs50-cyber-paloalto-oauth

CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)

authentication-authorizationctfeducation+3
10 months ago
Pwn ARM NFC preview

Pwn ARM NFC

GitLabaperikube/pwn-arm-nfc

ARM buffer overflow challenge exploiting NFC tag input on Raspberry Pi. Includes hardware assembly guide, server code, and flag retrieval for CTF and…

binary-exploitationctfeducation+3
18 years ago
Aperisite preview

Aperisite

GitLabaperikube/aperisite

CTF team website aggregating writeups and resources for web security challenges including XSS, SQLi, CSRF, SSRF, and XXE.

ctfeducationweb-security
44 years ago
Compose Aperisite preview

Compose Aperisite

GitLabaperikube/compose-aperisite

Docker Compose wrapper to deploy AperiSite, a curated platform hosting CTF writeups, security challenges, and educational resources covering web,…

ctfcurated-resourceseducation+1
15 years ago
mas-crackmes preview

mas-crackmes

GitHubowasp/mas-crackmes

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

android-securitybinary-analysisctf+6
333 years ago
OWASP-Learning-Gateway preview

OWASP-Learning-Gateway

GitHubowasp/owasp-learning-gateway

OWASP Learning Gateway Project

ctfcurated-resourceseducation+3
143 years ago
Exploiting-a-vulnerability-using-reverse-shell preview

Exploiting-a-vulnerability-using-reverse-shell

GitHubdampedcoast/exploiting-a-vulnerability-using-reverse-shell

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

ctfeducationexploitation+5
2 months ago
Zero-Day-Legacy preview

Zero-Day-Legacy

GitHubayham-megdadi/zero-day-legacy

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

ctfeducationlabs-practice+6
11 month ago
dcsgonebadge preview

dcsgonebadge

GitLabcryptoadvocate/dcsgonebadge

The hardware engineering home of the Circuit Crafters first electronic badge project.

cryptographyctfeducation+2
14 months ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
5 months ago
Previous1234Next