Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
890 results
cve-2022-27255 preview

cve-2022-27255

GitHubinfobyte/cve-2022-27255

Automated firmware analysis and exploit toolkit for CVE-2022-27255, a Realtek eCos SDK SIP ALG buffer overflow affecting 30+ router models. Includes…

binary-analysisctfeducation+7
284
4 years ago
PolyEngine preview

PolyEngine

GitHublongwayhomie/polyengine

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

anti-botbinary-analysisctf+6
15726 days ago
CVE-2025-21756 preview

CVE-2025-21756

GitHubh3raklez/cve-2025-21756

Educational lab demonstrating a use-after-free (UAF) exploit in the Linux kernel's vsock subsystem for local privilege escalation to root, with…

binary-exploitationctfeducation+4
15 months ago
spectrIDA-Reverse_Engineering_Stack preview

spectrIDA-Reverse_Engineering_Stack

GitHubggfuchsi-oss/spectrida-reverse_engineering_stack

Parallel IDA Pro binary analysis with AI-powered function naming, Neo4j knowledge graph, and phantomrt emulation/hooking/fuzzing engine for automated…

ai-assisted-reversingbinary-analysisctf+8
611 month ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
11.5k29 days ago
PentestGPT preview

PentestGPT

GitHubgreydgl/pentestgpt

Automated Penetration Testing Agentic Framework Powered by Large Language Models

ai-securityctfeducation+6
15.2k1 month ago
caldera preview

caldera

GitHubapache/caldera

Automated Adversary Emulation Platform

adversarial-attackcommand-and-controlctf+7
7.2k6 days ago
ROPgadget preview

ROPgadget

GitHubjonathansalwan/ropgadget

Search for ROP gadgets in ELF, PE, Mach-O, and Raw binaries across x86, ARM, MIPS, and RISC-V architectures. Supports automated ROP chain generation…

binary-analysisbinary-exploitationctf+3
4.5k2 months ago
AperiSolve preview

AperiSolve

GitHubzeecka/aperisolve

Automated steganalysis platform that detects hidden data in images using 16 parallel analyzers, bit-layer visualization, and an in-app wiki for CTF…

cryptographyctfeducation+2
8418 days ago
exrop preview

exrop

GitHubd4em0n/exrop

Automated ROP chain generator for x86-64 binaries using symbolic execution. Supports register/memory writes, function calls, syscalls, badchar…

binary-exploitationctfexploit-frameworks+2
3105 months ago
jwtXploiter preview

jwtXploiter

GitHubdontpanico/jwtxploiter

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

ctfexploitationpenetration-testing+2
2895 years ago
Owasp-top-10-k8s-2025 preview

Owasp-top-10-k8s-2025

GitHubhac01/owasp-top-10-k8s-2025

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

cloud-securitycontainer-securityctf+8
481 month ago
CVE-2015-1328-GoldenEye preview

CVE-2015-1328-GoldenEye

GitHubelit3pwner/cve-2015-1328-goldeneye

Automated local privilege escalation exploit for CVE-2015-1328 targeting Ubuntu overlayfs, designed for CTF environments with a simple bash…

ctfexploitationpenetration-testing+2
101 year ago
ludus_crushftp_cve-2025-31161_sim preview

ludus_crushftp_cve-2025-31161_sim

GitHubrufflabs/ludus_crushftp_cve-2025-31161_sim

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

ctfeducationexploitation+5
2 months ago
CVE-2026-20896 preview

CVE-2026-20896

GitHubkaleth4/cve-2026-20896

Automated PoC exploit for CVE-2026-20896, a Gitea authentication bypass via directory traversal in the API authorization header, enabling…

authentication-authorizationctfexploitation+3
12 months ago
lab-cve-2023-4863 preview

lab-cve-2023-4863

GitHubpixelotes/lab-cve-2023-4863

Docker-based lab to reproduce CVE-2023-4863 (heap buffer overflow in libwebp) with automated crash demonstration, patched vs vulnerable comparison,…

binary-exploitationctfeducation+3
3 months ago
CVE-2022-46364-htb-ctf preview

CVE-2022-46364-htb-ctf

GitHubjwsly12/cve-2022-46364-htb-ctf

Exploit CVE-2022-46364 in Apache CXF 3.2.14 for LFI and SSRF via MTOM/XOP injection. Automated multipart construction and Base64 extraction for HTB…

ctfexploitationlabs-practice+3
15 months ago
CVE-2022-26923 preview

CVE-2022-26923

GitHubnefhara/cve-2022-26923

Automated CVE-2022-26923 Exploitation (Certifried)

authenticationctfeducation+6
3 months ago
Previous12…50Next