Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
CVE-2023-38408 preview

CVE-2023-38408

GitHubwxrdnx/cve-2023-38408

Slide deck and source code analyzing CVE-2023-38408, detailing the exploit methodology and attack vectors for educational security research.

ctfeducationexploitation+2
1 year ago
CVE-2025-49132_HTB_SEASON10 preview

CVE-2025-49132_HTB_SEASON10

GitHubahmedf000/cve-2025-49132_htb_season10

Unauthenticated RCE exploit for CVE-2025-49132 in Pterodactyl Panel via path traversal, PEAR command injection, and PHP code execution. Includes HTB…

ctfeducationexploitation+3
6 months ago
audit-xss-cve-2020-7934 preview

audit-xss-cve-2020-7934

GitHubgiardinas-dev/audit-xss-cve-2020-7934

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

ctfeducationexploitation+3
4 years ago
awesome-ai-security preview

awesome-ai-security

GitHubgmh5225/awesome-ai-security

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

adversarial-attackai-securityctf+7
442 days ago
jwt-key-confusion-poc preview

jwt-key-confusion-poc

GitHubaalex954/jwt-key-confusion-poc

JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction

ctfexploitationpayload-generation+3
24 years ago
bordair-detector preview

bordair-detector

GitHubjosh-blythe/bordair-detector

Two-stage prompt-injection and jailbreak detector: regex gates plus a quantised DeBERTa-v3 ONNX classifier, with image, document, and audio support.…

adversarial-attackai-securitycode-analysis+5
1 month ago
Digital-Signature-Forgery-Attack preview

Digital-Signature-Forgery-Attack

GitHubdemining/digital-signature-forgery-attack

How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX

cryptographyctfcurated-resources+3
41 year ago
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k2 months ago
Pentest-Bookmarkz preview

Pentest-Bookmarkz

GitHubsofianehamlaoui/pentest-bookmarkz

A collection of useful links for Pentesters

ctfcurated-resourceseducation+9
1801 year ago
Explosive-As-Hell-MCS-Qualifer-Web-500 preview

Explosive-As-Hell-MCS-Qualifer-Web-500

GitHubabdullahmaqbool22/explosive-as-hell-mcs-qualifer-web-500

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

binary-exploitationctfeducation+7
4 months ago
fas-judgement-oss preview

fas-judgement-oss

GitHubfallen-angel-systems/fas-judgement-oss

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

adversarial-attackai-securityctf+8
135 months ago
RsaCtfTool preview

RsaCtfTool

GitHubrsactftool/rsactftool

RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data

cryptographyctfeducation+3
7.1k27 days ago
payloads preview

payloads

GitHubfoospidy/payloads

Git All the Payloads! A collection of web attack payloads.

ctfcurated-resourceseducation+6
4.0k5 years ago
EntraGoat preview

EntraGoat

GitHubsemperis/entragoat

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

authenticationcloud-securityctf+7
9814 months ago
BadZure preview

BadZure

GitHubmvelazc0/badzure

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

cloud-securityctfeducation+6
52411 days ago
smart-contract-attack-vectors preview

smart-contract-attack-vectors

GitHubharendra-shakya/smart-contract-attack-vectors

A curated list of smart contract attack vectors

ctfcurated-resourcesdefensive-tools+3
5232 years ago
htb-writeups preview

htb-writeups

GitHubmomenbasel/htb-writeups

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

ctfcurated-resourceseducation+7
2421 month ago
dcipher-cli preview

dcipher-cli

GitHubk4m4/dcipher-cli

🔓Crack hashes using online rainbow & lookup table attack services, right from your terminal.

cryptographyctfhash-analysis+1
2335 years ago
Previous123Next