Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
999 results
linux-smart-enumeration preview

linux-smart-enumeration

GitHubdiego-treitos/linux-smart-enumeration

Linux enumeration tool for pentesting and CTFs with verbosity levels

ctfinformation-gatheringpenetration-testing+2
4.0k
3 months ago
Steganography preview

Steganography

GitHubragibson/steganography

LSB steganography tool for hiding and extracting data in BMP/PNG images and WAV audio files, with built-in steganalysis detection for bitmap images.

cryptographyctfeducation+2
66110 months ago
crypto_identifier preview

crypto_identifier

GitHubacceis/crypto_identifier

Crypto tool for pentest and ctf : try to uncipher data using multiple algorithms and block chaining modes. Usefull for a quick check on unknown…

cryptographyctfencryption-decryption-tools+1
1278 years ago
CVE-2025-29775 preview

CVE-2025-29775

GitHubethicalpap/cve-2025-29775

Educational lab environment demonstrating SAMLStorm (CVE-2025-29775) vulnerability in xml-crypto library. Includes vulnerable SAML service provider,…

ctfeducationlabs-practice+3
11 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcarlosaruy/cve-2025-55182

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

ctfeducationexploitation+6
8 months ago
cnappgoat preview

cnappgoat

GitHubtenable/cnappgoat

Multi-cloud vulnerable-by-design environment deployment tool for practicing detection and exploitation of cloud security misconfigurations across…

cloud-infrastructure-securitycloud-securityctf+5
2962 years ago
React-Server-Components-RCE preview

React-Server-Components-RCE

GitHubgelukcrab/react-server-components-rce

GUI-based RCE exploit tool for React Server Components and Next.js (CVE-2025-55182). Supports command execution, memory shell injection, reverse…

command-and-controlctfeducation+8
108 months ago
INT14107_CVE-2021-35042 preview

INT14107_CVE-2021-35042

GitHubvutiendat323/int14107_cve-2021-35042

Django-based CTF blog platform with integrated CVE-2021-35042 exploit tool for learning web application security and vulnerability exploitation.

ctfeducationexploitation+3
4 months ago
jwtXploiter preview

jwtXploiter

GitHubdontpanico/jwtxploiter

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

ctfexploitationpenetration-testing+2
2905 years ago
WEB-CLI_RCE_React2Shell preview

WEB-CLI_RCE_React2Shell

GitHubraivenlockdown/web-cli_rce_react2shell

Educational PoC exploit for CVE-2025-55182 (Next.js Prototype Pollution) with interactive web CLI, single-command mode, and reverse shell for CTF and…

ctfeducationexploitation+5
62 months ago
binwalk preview

binwalk

GitHubrefirmlabs/binwalk

Fast firmware analysis tool that identifies, extracts, and analyzes embedded files and data using signature scanning and entropy analysis, re-written…

binary-analysisctfdata-recovery+8
14.3k14 days ago
CVE-2025-8110 preview

CVE-2025-8110

GitHubixzodiak/cve-2025-8110

Proof-of-concept exploit for CVE-2025-8110, a Gogs RCE via symlink file-update API. Authenticates, injects malicious git config, and triggers a…

ctfeducationexploitation+4
1 month ago
CVE-2025-8110-Silentium-HTB preview

CVE-2025-8110-Silentium-HTB

GitHubhassan-hamadi/cve-2025-8110-silentium-htb

Proof-of-concept exploit for CVE-2025-8110, a Gogs RCE via symlink file-update API. Authenticated attacker overwrites .git/config to inject…

ctfeducationexploitation+3
4 months ago
pwninit preview

pwninit

GitHubio12/pwninit

Automates setup of binary exploitation challenges by patching ELF binaries, fetching matching linkers, unstripping libc, and generating pwntools…

binary-exploitationctfexploitation+2
1.1k28 days ago
ctf-party preview

ctf-party

GitHubnoraj/ctf-party

:triangular_flag_on_post: A CLI tool & library to enhance and speed up script/exploit writing with string conversion/manipulation.

ctfscripting-automationutilities-frameworks
9015 days ago
DataSurgeon preview

DataSurgeon

GitHubdrew-alleman/datasurgeon

Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

ctfdata-exfiltrationforensics+6
9032 years ago
jwt_tool preview

jwt_tool

GitHubticarpi/jwt_tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

api-securityapi-security-testingcryptography+5
6.8k1 year ago
cryptovenom preview

cryptovenom

GitHublockedbyte/cryptovenom

Comprehensive cryptography toolkit implementing classical ciphers, modern symmetric/asymmetric encryption, hash algorithms, encoding schemes, and…

cryptographyctfeducation+3
25 years ago
Previous12…56Next