Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
circuit-artist preview

circuit-artist

GitHublets-all-be-stupid-forever/circuit-artist

Digital logic simulation game with event-driven engine, propagation delays, and campaign system for learning circuit design through pixel-based NAND…

ctfeducationhardware-security+2
474
1 month ago
osx-password-dumper preview

osx-password-dumper

GitHubjeanpeyremesmots/osx-password-dumper

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

ctfpassword-crackingpenetration-testing+2
531 year ago
ssh-chatter preview

ssh-chatter

GitHubgosuda/ssh-chatter

Modern C SSH/TELNET bulletin board system with AI-moderated chat, retro BBS features, file transfers, RSS reader, and JSON automation API. Supports…

ai-securityauthenticationctf+6
3314 days ago
AI-Vulnerabilities-Playground preview

AI-Vulnerabilities-Playground

GitHubowasp/ai-vulnerabilities-playground

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

adversarial-attackai-securityctf+4
133 months ago
CVE-2022-44268 preview

CVE-2022-44268

GitHubentr0pie/cve-2022-44268

Proof-of-concept exploit for ImageMagick arbitrary file read vulnerability (CVE-2022-44268) via crafted PNG textual chunks, enabling extraction of…

ctfeducationexploitation+2
133 years ago
Mahoraga-Webapp-Defender preview

Mahoraga-Webapp-Defender

GitHubageofalgorithms/mahoraga-webapp-defender

AI-powered reactive website defense system that detects attacks, analyzes them, and autonomously patches source code in real-time using LLM agents.

ai-securityapi-securityctf+6
43 months ago
HTB-NanoCorp-CVE-2024-0670 preview

HTB-NanoCorp-CVE-2024-0670

GitHubdfdxarjy/htb-nanocorp-cve-2024-0670

PowerShell exploit for CVE-2024-0670, abusing CheckMK Agent MSI repair to escalate from low-privileged user to SYSTEM on Windows targets. Designed…

binary-exploitationctfeducation+5
2 months ago
wvctf preview

wvctf

GitHubsyn-4ck/wvctf

Gamified web platform for pentesting and web application security training. Users find flags in a vulnerable app to learn about common web…

ctfeducationlabs-practice+3
12 years ago
BlueDoor preview

BlueDoor

GitHubsethwhy/bluedoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative…

ctfeducationexploitation+7
21 year ago
CVE-2026-11518-XSS preview

CVE-2026-11518-XSS

GitHubxmyronn/cve-2026-11518-xss

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

ctfeducationpenetration-testing+3
3 months ago
CVE-2025-8018 preview

CVE-2025-8018

GitHubdrackyjr/cve-2025-8018

Python PoC exploit for CVE-2025-8018, a critical unauthenticated SQL injection in Food Ordering Review System v1.0. Supports time-based blind and…

ctfeducationexploitation+3
21 year ago
Snow Crash preview

Snow Crash

GitLabqduarte-42/snow-crash

Hands-on cybersecurity curriculum introducing system exploitation, privilege escalation, and vulnerability analysis through 14 progressive…

binary-exploitationctfeducation+4
10 months ago
CVE-2025-46173 preview

CVE-2025-46173

GitHubpruthuraut/cve-2025-46173

Proof-of-concept for CVE-2025-46173, a stored XSS vulnerability in Online Exam Mastering System 1.0. Includes injection steps, trigger mechanism, and…

ctfeducationexploitation+3
1 year ago
ctf preview

ctf

GitLabheathen42/ctf

Curated collection of CTF challenge solutions covering binary exploitation, reverse engineering, and system security with detailed write-ups.

binary-exploitationctfeducation+1
5 years ago
base-drupal preview

base-drupal

GitHubcved-sources/base-drupal

Docker base image for vulnerable Drupal 8.3.0, used in security training and penetration testing labs via the Cved vulnerable container management…

ctfeducationlabs-practice+2
5 years ago
Why-so-Serious-SAM preview

Why-so-Serious-SAM

GitHubp1rat3r00t/why-so-serious-sam

PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

ctfeducationexploitation+6
1 year ago
Trickster-HTB preview

Trickster-HTB

GitHubpallangyo98/trickster-htb

Step-by-step exploitation report for the Trickster HTB machine, chaining XSS in PrestaShop, SSTI in ChangeDetection.io, and privilege escalation via…

ctfeducationexploitation+5
1 year ago
CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE preview

CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50365_csrf_delete_category-phpgurukul-cve

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

ctfeducationexploitation+3
1 year ago
Previous12Next